Hi,
After using search command I got the following output for XYZ field
/mrIWeb/Images/SE/2.1/lib/qstudio/qcreator/qcore/QWidget.js
/mrIWeb/Images/SE/2.0/source/js/SurveyEngine.js
/mrIWeb/Images/SE/1.7.1/lib/qstudio/qcreator/qcomponent/BtnMatrix.js
/mrIWeb/Images/SE/1.8/lib/qstudio/qcreator/qcomponent/DragnDrop.js
but I dont want my output like this,
I want to display my output like
/mrIWeb/Images/SE/2.1
/mrIWeb/Images/SE/2.0
/mrIWeb/Images/SE/1.7.1
/mrIWeb/Images/SE/1.8
is it possible can you help to resolve this
Thanks
I would do it with an eval and Rex, something along the following addition to the search
... | rex field=XYZ "(?<XYZ_trimmed>(\/[^\/]*){4})\/.*"
should give you the desired trimmed result in the field XYZ_trimmed, see http://docs.splunk.com/Documentation/Splunk/6.1.5/SearchReference/Rex
I would do it with an eval and Rex, something along the following addition to the search
... | rex field=XYZ "(?<XYZ_trimmed>(\/[^\/]*){4})\/.*"
should give you the desired trimmed result in the field XYZ_trimmed, see http://docs.splunk.com/Documentation/Splunk/6.1.5/SearchReference/Rex
Thank you so much