All,
My first time messing with data manipulation at the heavy forwarder tier. Specifically looking to CIM a field my developers can't fix at code. Essentially quick sub elapsedTime to duration.
Version: Splunk 6.32/UF 6.24
Linux CentOS 6.x
props.conf
[log4j]
SED-alter = y/elapsedTime/duration/
You should use 's/...' instead of 'y/...'
props.conf
[log4j]
SED-alter = s/elapsedTime/duration/g
You should use 's/...' instead of 'y/...'
props.conf
[log4j]
SED-alter = s/elapsedTime/duration/g
Switched it to SEDCMD and it worked
[log4j]
SEDCMD-alter = s/elapsedTime/duration/g
So both string should be of same lenght
Okay, tried to s//g version, and restarted the heavy forwarder. Unfortunately no luck. Still seeing elapsedTime coming in.
Any idea where I might be going wrong?
check the sourcetype does match and SED-alter
is unique