Hello,
I am looking to clean up the result data from a Splunk query.
How do I remove all the text prior to the user name at the end of the line?
Server1234.prod.outlook.com/Microsoft Exchange Hosted Organizations/MyOrg.onmicrosoft.com/Smith, Joe
I want the results to just return "Smith, Joe"
thoughts?
| makeresults 1
| eval _raw="Server1234.prod.outlook.com/Microsoft Exchange Hosted Organizations/MyOrg.onmicrosoft.com/Smith, Joe"
| rex mode=sed "s/.*\///g"
| table _raw