Splunk Search

multikv - remove unwanted rows from results

axsolis
Path Finder

Hi, I am successfully using multikv to parse my tabular data. However, my data has row separators and other non-intesting data that I would like to omit from the results. Is there a way to do this?

For example, The original data looks like this:

**This is data for XXXXX**

Heading1 Heading2 Heading3

-------------------------------------------
fieldA1 fieldA2 fieldA3
fieldB1
fieldB2 fieldB3
fieldC1 fieldC2
fieldC3

**This is data for XXXXX**

Heading1 Heading2 Heading3

-------------------------------------------
fieldA1 fieldA2 fieldA3
fieldB1
fieldB2 fieldB3
fieldC1 fieldC2
fieldC3

I obviously want to omit the lines starting with "**" and "--" from the results. How can I do this?

Thanks!

Tags (3)
0 Karma
1 Solution

aelliott
Motivator

axsolis
Path Finder

That worked. I just placed the regex command after the multikv and it omitted the lines I wanted from the search. Thanks!

|multikv|regex _raw="^[^(-|\*).*$].*$"

Above I remove lines starting with "-" and "*".

0 Karma

aelliott
Motivator

with slightly different regex

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...