Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I get the next to the last value(or field) of a record??

$
0
0
I have data that looks like this; When I perform my search the data returned by splunk looks like this on the dashboard; date="date" username="username filename="filename" 1000 bytes You can see the problem... I can grab all of the "keyed" fields but I cant get the value "1000 bytes" because its not keyed. If I had awk I could grab the second to the last value of the string and I would be done. Is there a way to grab the value "1000" above and place it into a value to inject into my tables??? Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>