Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to remove everything after a colon in an existing field?

$
0
0
I have a field that contains both IP address and port number separated by a semicolon (example 10.1.1.1:23) How do I use rex to trim off the port# leaving me with just the IP address?

Viewing all articles
Browse latest Browse all 47296

Trending Articles