Remove punct field

How do I keep the punct field when sending from a Splunk UF through stream

We wrote a custom function called ‘rebuild_punct’ to do this. Stick it at the end of your pipeline to create punct based on _raw.

How to create a custom function:
Info on the contents of punct:

You could use something like this:

punct = _raw.substr(0, 150).replace(/[0-9A-Za-z_*\s/]/g, '')