Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I edit my "rex mode=sed..." statement to remove square brackets and the content within them from a field?

$
0
0
Hi, I need to remove square brackets and content within it from a field in a search. eg: Input: My name is John [Employee] Output: My name is John I tried with the following expression: rex mode=sed field="name" "s/\[[^]]*//" It returns output as: `My name is John ]` I don't want the closing square bracket. How do I modify the above pattern so that I get the desired output? Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>