Getting Data In

index time SED from props.conf

jbower
New Member

Are the SED commands in props.conf excuted in order? In other words

Note: (All the following is under [default])

Can I write a test to set a field so it will fail a SED test

SEDCMD-callid =s/(.*callid)(=)(.*)/\1~\3/g

then run the main SED test

SEDCMD-ssnmask = s/(.*[ :=;,])(?!000)(?!666)(?!9)\d{3}[ -](?!00)\d\d[ -](?!0000)(\d{4}[ =;,&].*)/\1###SSN-SCRUBBED###\2/g
SEDCMD-ssnmask1 = s/(.*[ :=;,])(?!000)(?!666)(?!9)\d{3}(?!00)\d\d(?!0000)(\d{4}[ ;,&=].*)/\1###SSN-SCRUBBED###\2/g

and then change it back

SEDCMD-callid_fix =s/(.*callid)(~)(.*)/\1=\3/g

or might the indexer not always run the SED commands in that order?

Tags (1)
0 Karma

jbower
New Member

I found how you do it (put all the SED commands on one line)
so

SEDCMD-Master = s/(.[ :=;,])(?!000)(?!666)(?!9)d{3} -dd -(d{4}[ =;,&].)/1###SSN-SCRUBBED###2/g s/(.[ :=;,])(?!000)(?!666)(?!9)d{3}(?!00)dd(?!0000)(d{4}[ ;,&=].)/1###SSN-SCRUBBED###2/g

and then thay will get excuted in order.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...