<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trying to properly perform an ingestion time SED in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-perform-an-ingestion-time-SED/m-p/678617#M113404</link>
    <description>&lt;P&gt;Sorry, I made a typo in the search time that gets me what I need it was supposed to say:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;| eval CommandHistory = commandHistory_sed&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;I can make the effect happen in search time, the issue is I need to figure out how to have this effect applied at ingest time so the effect is automatically applied to all of the events.&lt;/P&gt;</description>
    <pubDate>Sun, 25 Feb 2024 20:41:10 GMT</pubDate>
    <dc:creator>Cornisgud</dc:creator>
    <dc:date>2024-02-25T20:41:10Z</dc:date>
    <item>
      <title>Trying to properly perform an ingestion time SED</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-perform-an-ingestion-time-SED/m-p/678615#M113402</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Currently I'm attempting to make a CommandHistory field a bit more readable for our analysts but I'm having trouble getting the formatting correct or maybe I'm just using the wrong command or taking the wrong approach.&lt;BR /&gt;&lt;BR /&gt;Basically our EDR dumps recent commands ran on a system into the CommandHistory field separated by a&amp;nbsp;¶ symbol. I'm trying to just replace that with a new line at ingestion time.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Made up example of what's in CommandHistory at the moment (I don't want to use real data I apologize):&lt;/STRONG&gt;&lt;BR /&gt;command1 -q lifeishard¶ReallyLong Command -t LifeIsHarderWhenYouCantFigureItOut¶ThirdCommand -u switchesare -cool¶One more command&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;The search time commands that get me what I want in a field called commandHistory_sed:&lt;/STRONG&gt;&lt;BR /&gt;| eval commandHistory = CommandHistory&lt;BR /&gt;| rex field=commandHistory_sed mode=sed "s/\¶/\n/g"&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;This ends up looking like this:&lt;/STRONG&gt;&lt;BR /&gt;command1 -q lifeishard&lt;BR /&gt;ReallyLong Command -t LifeIsHarderWhenYouCantFigureItOut&lt;BR /&gt;ThirdCommand -u switchesare -cool&lt;BR /&gt;One more command&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;What I've tried in props.conf:&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;SEDCMD-substitute = 's/\¶/\n/g'&lt;BR /&gt;&amp;nbsp;SEDCMD-alter = 's/\¶/\n/g'&lt;BR /&gt;&lt;BR /&gt;Neither work. We have many other Eval and FIELDALIAS statements under this sourcetype in props.conf that are functioning fine so I think I'm just not formatting the SED properly or I'm not taking the right approach.&lt;BR /&gt;&lt;BR /&gt;Does anyone have any advice on what I am doing wrong and what I need to do to achieve the result?&lt;BR /&gt;&lt;BR /&gt;Thank you for any help in advance!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2024 19:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-perform-an-ingestion-time-SED/m-p/678615#M113402</guid>
      <dc:creator>Cornisgud</dc:creator>
      <dc:date>2024-02-25T19:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to properly perform an ingestion time SED</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-perform-an-ingestion-time-SED/m-p/678616#M113403</link>
      <description>&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;rex&lt;/FONT&gt; command needs the name of an existing field in the &lt;FONT face="courier new,courier"&gt;field&lt;/FONT&gt; option.&amp;nbsp; Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval commandHistory = CommandHistory
| rex field=commandHistory mode=sed "s/\¶/\n/g"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2024 20:35:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-perform-an-ingestion-time-SED/m-p/678616#M113403</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-02-25T20:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to properly perform an ingestion time SED</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-perform-an-ingestion-time-SED/m-p/678617#M113404</link>
      <description>&lt;P&gt;Sorry, I made a typo in the search time that gets me what I need it was supposed to say:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;| eval CommandHistory = commandHistory_sed&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;I can make the effect happen in search time, the issue is I need to figure out how to have this effect applied at ingest time so the effect is automatically applied to all of the events.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2024 20:41:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trying-to-properly-perform-an-ingestion-time-SED/m-p/678617#M113404</guid>
      <dc:creator>Cornisgud</dc:creator>
      <dc:date>2024-02-25T20:41:10Z</dc:date>
    </item>
  </channel>
</rss>

