Splunk Search

use regex to remove a number from a string

matansocher
Contributor

Hi,

I want to remove a number (up to 5 digits) from a string on its beginning.
an example:

43.aaaa_vvvvv.cccccc:dddddd => aaaa_vvvvv.cccccc:dddddd
9374.aaaa_vvvvv.cccccc:dddddd => aaaa_vvvvv.cccccc:dddddd
1.aaaa_vvvvv.cccccc:dddddd => aaaa_vvvvv.cccccc:dddddd

I only need to remove the first number and the "." after it.

thanks

0 Karma
1 Solution

niketn
Legend

@matansocher, is this a field or raw data?
You can try the following rex command:

<your base search>
| rex field=_raw "\d+.(?<myData>.*)"
| table _raw myData

I have use field name as _raw but you can replace with your own if it is some other field. Alternatively you can also use replace() command with regular expression if this is a field.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

0 Karma

nikita_p
Contributor

Hi matansocher,
Try the regex below. Let me know if this works.
index=xyz| rex field=_raw "^(?P[^.]+)"

0 Karma

ryhluc01
Communicator

This produces this message:

"Error in 'rex' command: Encountered the following error while compiling the regex '^(?P[^.]+)': Regex: unrecognized character after (?P"

0 Karma

niketn
Legend

@matansocher, is this a field or raw data?
You can try the following rex command:

<your base search>
| rex field=_raw "\d+.(?<myData>.*)"
| table _raw myData

I have use field name as _raw but you can replace with your own if it is some other field. Alternatively you can also use replace() command with regular expression if this is a field.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...