Hi, I am checking for underscore in field values and if it present then capture that value. For Example: if name has underscore in it then value should get assigned to APP field and if it does n...
Hi Splunkers, I have a doubt about underscores and path in props.conf. Suppose, in my props.conf, I have: [source::/aaa/bbb/ccc_ddd] As you can see, in my path I have an underscore in path name....
...ried the search with the Field discovery turned on and off. The results were the same.
It looks like there is a difference in how Splunk reacts to the underscore in searches.
I had treated it as a...
...ed field=attachment "s/ /_/g" to replace the whitespace with underscores.
Question: How do I go about ignoring the whitespace before and after the dash. I am getting Filename_ABC_- _...
...f my field names for this sourcetype, except for the new field name "MYMESSAGE" have an underscore at the end just like this RecordID_ Timestamp_
Anyone run into this issue before and know how to r...
...nds with "_Blah". The problem is that I also have a value that is "_OtherBlah" which is being matched. I'm assuming I need to do something to escape the underscore, but I can't seem to find how to do it....
How does one get at fields in _internal that are prefixed with an underscore, e.g. _tcp_KBps ? It seems that Splunk is masking these somehow, preventing them from being visible to stats, t...
I have a value a_b_c. How do I extract the last '_' item. So in this case it'd be 'c'. The number of of underscores in the field can change. I need the last one.
I'm trying to create a regex that removes everything before the second underscore in a string. The number of characters before the second underscore varies.
For example:
DR300_Corp_76
B...