Splunk Search

replace multivalue field values

mariobisio
Explorer

Hi guys,

I'm trying to replace values in an irregular multivalue field.

I don't want to use mvexpand because I need the field remains multivalue.

Here some examples of my multivalues fields

#1

115000240259839935-619677868589516300
1003000210260195023-294635473830872390
1003000210260241553-580541817408914764
531000140235102831-490142552617583496
115000240260262212-692365156372645389
 
#2
448000250026778748-44531981890881098
1286000030219284359-851572649149989069
 
I told irregular because the multivalue field could be compose by 1 or n values.
 
My goal is to keep only the numerical part before the "-"
for example:
the #1 should became
 
115000240259839935
1003000210260195023
1003000210260241553
531000140235102831
115000240260262212
 
the #2 should become:
448000250026778748
1286000030219284359
 
Thanks in advance for your help
 
Regards
Mario
Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| eval yourfield=mvmap(yourfield,mvindex(split(yourfield,"-"),0))

View solution in original post

to4kawa
Ultra Champion
| makeresults 
| eval field1="115000240259839935-619677868589516300
1003000210260195023-294635473830872390
1003000210260241553-580541817408914764
531000140235102831-490142552617583496
115000240260262212-692365156372645389"
| eval field2="448000250026778748-44531981890881098
1286000030219284359-851572649149989069"
| rename COMMENT as "from here, the logic"
| rex max_match=0 field=field1  "(?<result1>(?m)^\d+)"
| rex max_match=0 field=field2  "(?<result2>(?m)^\d+)"

How about rex?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval yourfield=mvmap(yourfield,mvindex(split(yourfield,"-"),0))

mariobisio
Explorer

Hi ITWhisperer,

this i s exactly what I was looking for.

Thank you very much

Great Job

 

Regards

Mario

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...

Splunk AppDynamics Agents Webinar Series

Mark your calendars! On June 24th at 12PM PST, we’re going live with the second session of our Splunk ...