Splunk Search

How to create a regex expression to mask the input?

poddraj
Explorer

Hi,
Can someone help with regex expression to mask the below kind of pattern. I need this pattern of text to be masked wherever I find it in my events.

12/KQXA/123456/ABXY --> **************ABXY 
11/VAXA/123456    /VAQY --> **************VAQY 
00/LCXA/545232/GYFT --> **************GYFT 
0 Karma

manjunathmeti
Champion

Try this query:

| makeresults | eval _raw="12/KQXA/123456/ABXY --> SPLUNKAAAAAAAAABXY" | append [| makeresults | eval _raw="11/VAXA/123456/VAQY      --> AAXZAAAAAAAAAAVAQY" ] | append [| makeresults | eval _raw="00/LCXA/545232/GYFT --> A1AAAAAX50AAAAAGYFT"] | rex field=_raw mode=sed "s/\w{14}/***************/g"
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...