Getting Data In

Correct syntax for syslog source in props.conf for SEDCMD

jbertoli
Engager

I would like to ensure that ssn's are anonymized, can anyone tell me what the source type should be for syslog? In the splunk browser the source shows up as udp:514, how should this be added to the source reference in the props.conf file. Cheers jb

[source::.../upd:514]
SEDCMD-accounts = s/ssn=\"\d{3}\-\d{2}\-\d{4}\"/=>\"xxx-xx-xxxx\"/g 
Tags (1)
0 Karma

ftk
Motivator

If you want to work off of the source field and the source is indeed udp:514, put this in your props.conf:

[source::udp:514]
SEDCMD-accounts = s/ssn=\"\d{3}-\d{2}-\d{4}\"/=>\"xxx-xx-xxxx\"/g

Or you could work off of whatever sourcetype is assigned to the data. If the sourcetype syslog is assigned, configure props.conf as follows:

[syslog]
SEDCMD-accounts = s/ssn=\"\d{3}-\d{2}-\d{4}\"/=>\"xxx-xx-xxxx\"/g
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...