<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Masking in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Masking/m-p/565988#M100657</link>
    <description>&lt;P&gt;Please help on this as i need to make the changes as soon as possible.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Sep 2021 09:19:47 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2021-09-06T09:19:47Z</dc:date>
    <item>
      <title>Masking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Masking/m-p/565937#M100653</link>
      <description>&lt;P&gt;Hello SPlunkers!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to mask below client secret event and for that i am using SEDCMD in props.conf. It is working fine in lab environment. But whenever i have used to deploy this changes in the production it is not working. Please guide me what i am doing wrong here9&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Below i have used.( SEDCMD i am using in Props)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SEDCMD-client-secret-1=s/client_secret=([A-Za-z0-9-.%#()_]+)/client_secret=********/g&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Below is my event:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;grant_type=client_credentials&amp;amp;client_id=dcqac926-6f0f-4784-bd5f-09fa13aeb73b&amp;amp;client_secret=.PM8o5kUF.R562yrqahj35_Lr6F%7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Sun, 05 Sep 2021 16:05:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Masking/m-p/565937#M100653</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2021-09-05T16:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: Masking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Masking/m-p/565942#M100654</link>
      <description>&lt;P&gt;It's a bit too little information to tell what's wrong.&lt;/P&gt;&lt;P&gt;Are you sure you're defining this sedcmd for the right sourcetype/source?&lt;/P&gt;&lt;P&gt;In case of a bigger architecture than all-in-one - are you deploying it in the proper place on the event's path? (on the ingest path, not on the search-head)&lt;/P&gt;&lt;P&gt;Do your events in prod environment look exactly the same as your lab ones?&lt;/P&gt;</description>
      <pubDate>Sun, 05 Sep 2021 17:01:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Masking/m-p/565942#M100654</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-05T17:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Masking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Masking/m-p/565944#M100655</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; Yes all the sourcetype settings are correct and i am picking for correct source and my deployment across deployment slaves are also correct.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Sep 2021 17:32:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Masking/m-p/565944#M100655</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2021-09-05T17:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Masking</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Masking/m-p/565988#M100657</link>
      <description>&lt;P&gt;Please help on this as i need to make the changes as soon as possible.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 09:19:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Masking/m-p/565988#M100657</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2021-09-06T09:19:47Z</dc:date>
    </item>
  </channel>
</rss>

