Splunk Search

rename data

haziqwebs
New Member

I want to rename CPU001 to CPU1, CPU_ALL to CPUALL, is it possible?alt text

0 Karma

somesoni2
Revered Legend

If you're looking to rename/update field values with CPU* format (not only CPU001 but CPU002 as well, give this try

Your current search | eval Jenis=replace(Jenis,"(00|_)","")
0 Karma

woodcock
Esteemed Legend

Like this:

... | replace "CPU001" WITH "CPU1" "CPU_ALL" WITH "CPUALL" IN Jenis

jmallorquin
Builder

Hi,

Yes, just put this at the end:

| eval Jenis = case (Jenis="CPU001","CPU1",Jenis="CPU_ALL","CPUALL")

Hope i help you

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...