Splunk Cloud Platform

concatenate syntax

verifi81
Path Finder

Hi folks

I'm providing a sample of many values I have for field: username

Field: username

Value: 

Roger Smith
Bob Dole
Randy Savage

I'm trying to create another field with the EVAL command called EMAIL and placing a dot between first name and last name followed by @Anonymous.com

Basically I'm trying to get the new field like this.

Field: Email

[email protected]
[email protected]
[email protected]

What would the syntax be?

 

Thanks in advance

Labels (1)
0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

@verifi81 

 

You should try something like this.

YOUR_SEARCH | eval email= replace(username," ",".")."@falcon.com" | table username email

 

Sample search.

 

| makeresults | eval _raw="
username
Roger Smith
Bob Dole
Randy Savage
" | multikv forceheader=1 | eval email= replace(username," ",".")."@falcon.com" | table username email

 

 

 

View solution in original post

0 Karma

verifi81
Path Finder

I stand corrected. It worked. Thank you!

0 Karma

verifi81
Path Finder

Hello Kamlesh,

My list of username is 1000 entries long so I won't be able to specify it like that. 

 

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@verifi81 

 

You should try something like this.

YOUR_SEARCH | eval email= replace(username," ",".")."@falcon.com" | table username email

 

Sample search.

 

| makeresults | eval _raw="
username
Roger Smith
Bob Dole
Randy Savage
" | multikv forceheader=1 | eval email= replace(username," ",".")."@falcon.com" | table username email

 

 

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...