Getting Data In

SEDCMD trouble- How to delete vfwew from field account?

bosseres
Contributor

Hello everyone!

I'm trying to make props file which will trim all not cyrillic symbols from field "account"

My log example is 

18:10:24 Object="some object" Source="some source1323" Account="Аккаунтvfweцw"

i want to delete vfwew from field Account, but note that symbols can go in any order and with cyrillic symbols too, i need to catch them all and delete, only from one field

SEDCMD-notcyr - Account="....

 

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

There is no way to do it with just a SEDCMD. The y command would match character class anywhere in the event and with s command you can't either restrict matching to a specific field (there is no notion of fields at this point at all) or match (for substitution) a string with holes in it.

Gr0und_Z3r0
Contributor

hi @bosseres 

Try something like this...

Gr0und_Z3r0_0-1680419020003.png

 

| makeresults 
| eval Account="Аккаунтvfweцw"
| rex field=Account mode=sed "s/[^А-Яа-я]+//g"
| table Account


~ If the reply helps, a Karma upvote would be appreciated

Get Updates on the Splunk Community!

Splunk is Nurturing Tomorrow’s Cybersecurity Leaders Today

Meet Carol Wright. She leads the Splunk Academic Alliance program at Splunk. The Splunk Academic Alliance ...

Part 2: A Guide to Maximizing Splunk IT Service Intelligence

Welcome to the second segment of our guide. In Part 1, we covered the essentials of getting started with ITSI ...

Part 1: A Guide to Maximizing Splunk IT Service Intelligence

As modern IT environments continue to grow in complexity and speed, the ability to efficiently manage and ...