SEDCMD in props.conf



In the Splunk GUI/Interface, I filter into the following commands to remove some unwanted data from being displayed:

| rex mode=sed field=_raw "s/ example: .+?( from |$)/ example: select from /g"
| rex mode=sed field=_raw "s/ in \(.+?\) / in (...) /g"

How would I apply this to props.conf in my forwarder (or is there a better option i.e. transforms.conf)?  I tried the following but did not seem to work for me. 

SEDCMD-first = s/ example: .+?( from |$)/ example: select from /g
SEDCMD-second = s/ in \(.+?\) / in (...) /g
force_local_processing = true

Labels (1)
0 Karma


Hi @irwinj_125,

It is better doing these replacements on your indexers without force_local_processing=true.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma



Yes my goal here is just to get the SEDCMD working, if I can do that I will disable local processing and set up on the indexer instead.  Doing this locally allows me to test without having to re-start the indexer, which would affect all my forwarders (at least that's my thinking).


0 Karma
Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...