I used below setting in props foe below sample data. But didn't help. Is that possible and how?
1.SEDCMD-Validated_time=sed "s/\"validated_time\":\"\d{4}-\d{2}-\d{2}\s+\d{2}:\d{2}:\d{2}\",/\"validated_time\":\"_time\"/g"
2.SEDCMD-Validated_time=sed "s/\"validated_time\":\"\d{4}-\d{2}-\d{2}\s+\d{2}:\d{2}:\d{2}\",/\"validated_time\":\"$_time\"/g"
3.SEDCMD-Validated_time=sed "s/\"validated_time\":\"\d{4}-\d{2}-\d{2}\s+\d{2}:\d{2}:\d{2}\",/\"validated_time\":\"$_time$\"/g"
exam_date: 2018-01-19
details: { [-]
grade: NEUTRAL
occurrences: { [-]
"validated_time":" 2018-01-19 16:51:28"
}
}
Thanks in advance.
|eval var=_time
I don't think SED commands can reference fields to build the replacement string.
What is your goal with this? Replacing a timestamp in the raw event with the content of _time? What is _time populated from and why would you want to override the raw event contents like this?