I have field name transport_route_id may contains non-alphanumeric characters but I want to remove all of them.
Does any know how can I remove them using | rex command?
This part seem cause error.
| field=transport_route_id mode=sed rex "[0-0a-zA-Z]"
The order of the options in the rex
command is wrong, and the regular expression has to be in a sed
script. This is more correct:
...| rex field=transport_route_id mode=sed "s/[^a-zA-Z0-9]//g"
See more in the docs.
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Rex
EDIT: forgot to link to docs...
/K
The order of the options in the rex
command is wrong, and the regular expression has to be in a sed
script. This is more correct:
...| rex field=transport_route_id mode=sed "s/[^a-zA-Z0-9]//g"
See more in the docs.
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Rex
EDIT: forgot to link to docs...
/K