Getting Data In

index time SED from props.conf

jbower
New Member

Are the SED commands in props.conf excuted in order? In other words

Note: (All the following is under [default])

Can I write a test to set a field so it will fail a SED test

SEDCMD-callid =s/(.*callid)(=)(.*)/\1~\3/g

then run the main SED test

SEDCMD-ssnmask = s/(.*[ :=;,])(?!000)(?!666)(?!9)\d{3}[ -](?!00)\d\d[ -](?!0000)(\d{4}[ =;,&].*)/\1###SSN-SCRUBBED###\2/g
SEDCMD-ssnmask1 = s/(.*[ :=;,])(?!000)(?!666)(?!9)\d{3}(?!00)\d\d(?!0000)(\d{4}[ ;,&=].*)/\1###SSN-SCRUBBED###\2/g

and then change it back

SEDCMD-callid_fix =s/(.*callid)(~)(.*)/\1=\3/g

or might the indexer not always run the SED commands in that order?

Tags (1)
0 Karma

jbower
New Member

I found how you do it (put all the SED commands on one line)
so

SEDCMD-Master = s/(.[ :=;,])(?!000)(?!666)(?!9)d{3} -dd -(d{4}[ =;,&].)/1###SSN-SCRUBBED###2/g s/(.[ :=;,])(?!000)(?!666)(?!9)d{3}(?!00)dd(?!0000)(d{4}[ ;,&=].)/1###SSN-SCRUBBED###2/g

and then thay will get excuted in order.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...