SEDCMD in props.conf



In the Splunk GUI/Interface, I filter into the following commands to remove some unwanted data from being displayed:

| rex mode=sed field=_raw "s/ example: .+?( from |$)/ example: select from /g"
| rex mode=sed field=_raw "s/ in \(.+?\) / in (...) /g"

How would I apply this to props.conf in my forwarder (or is there a better option i.e. transforms.conf)?  I tried the following but did not seem to work for me. 

SEDCMD-first = s/ example: .+?( from |$)/ example: select from /g
SEDCMD-second = s/ in \(.+?\) / in (...) /g
force_local_processing = true

Labels (1)
0 Karma


Hi @irwinj_125,

It is better doing these replacements on your indexers without force_local_processing=true.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma



Yes my goal here is just to get the SEDCMD working, if I can do that I will disable local processing and set up on the indexer instead.  Doing this locally allows me to test without having to re-start the indexer, which would affect all my forwarders (at least that's my thinking).


0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...