Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

In a search, How do I get the next to the last value(or field)?

$
0
0
I have data that looks like this; When I perform my search the data returned by Splunk looks like this on the dashboard: date="date" username="username filename="filename" 1000 bytes You can see the problem... I can grab all of the "keyed" fields, but I can't get the value "1000 bytes" because it's not keyed. If I had AWK, I could grab the second to the last value of the string and I would be done. Is there a way to grab the value "1000" above and place it into a value to inject into my tables??? Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>