Splunk Search

rex n replace or rex and optional find

TobiasBoone
Communicator

cs_username field contains multiple formats of username in the form of:
username
domain\usernam
username@domain.com

Q #1 How to I remove domain\ or @domian.com elegantly

&

Q #2 How do I deduplicate those usernames that have different case sensitivies
username
USERNAME

I just want one list of usernames to pipe back into a subsearch

Driving me crazy.

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Something like this?

main search foo [subsearch foo | eval username = lower(replace(username, "@.*", "")) | dedup username | fields username]

Removes everything after an @ symbol, converts to lower case, dedups, builds a huge OR'd expression to filter the main search.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Something like this?

main search foo [subsearch foo | eval username = lower(replace(username, "@.*", "")) | dedup username | fields username]

Removes everything after an @ symbol, converts to lower case, dedups, builds a huge OR'd expression to filter the main search.

martin_mueller
SplunkTrust
SplunkTrust

Does that mean your question is solved?

0 Karma

TobiasBoone
Communicator

I wasn't using eval in conjunction with the replace command correctly 😞

This example with another pipe to eval to get rid of the domain\ seems to be doing the trick. Thank you SO much.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...