Getting Data In

Why is the SEDCMD not working when ingesting a CSV via the web interface?

eugenek
Path Finder

Using the 7.0.1 web interface to ingest a CSV, and the SEDCMD command is not working. Tried reducing to the simplest possible scenario below.

alt text

0 Karma

eugenek
Path Finder

Upgraded to 7.1.0, and same issue.

0 Karma

micahkemp
Champion

You need a trailing slash (or more specifically, a slash to denote the end of your replacement string and the start of flags):

SEDCMD-test = y/o/O/

From the props.conf SEDCMD section:

substitute - y/string1/string2/
0 Karma

eugenek
Path Finder

Good catch. I was trying to come up with the simplest example possible, and had a typo. However, it still doesn't work (screenshot updated). Does it work for you?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...