Splunk Search

remove all text before certain words in events

trilocho
Loves-to-Learn

I have events like below

-a3bcd: Info1234x:NullValue

-a3bcd: Info1234x:NullValue

-b3bcd: Info1234x:NullValue2

-c3bcd: Info1234x:NullValue3

 

I managed to produce a table like these

ErrorInfo                                                     Count

a3bcd: Info1234x:NullValue               2

-b3bcd: Info1234x:NullValue2           1

-c3bcd: Info1234x:NullValue3           1

I would like to condense those events into one since they are all same kind of error just different paramter

so it would be like

ErrorInfo                                                     Count

Info1234x:                                                   1


Thanks in advance

 

 

 

 

Labels (3)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval ErrorInfo = mvindex(split(ErrorInfo, ":"),1)
0 Karma

trilocho
Loves-to-Learn

It didt work

0 Karma
Get Updates on the Splunk Community!

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...