Splunk Dev

Rex Field=All Fields mode=sed

tuanledang1120
Engager

Hi,

I'm trying to do a sed (replacing comma with _) on all fields, instead of having to specify which field I want to do the sed command on. Is that possible?

I tried to do field=*, but that did not work.

Thanks.

Tags (1)
0 Karma
1 Solution

javiergn
Super Champion

Alternatively you could use foreach:

| foreach * [eval <<FIELD>>=replace(<<FIELD>>, ",", "_" )]

View solution in original post

ddrillic
Ultra Champion

If you like, you can take it to props.conf.

We do the following to remove spaces -

# :"   kkkki    " -- remove spaces
SEDCMD-trim-ws1 = s/(:\")(\s+)?(\w+)(\s+)?(\")/\1\3\5/g

So, it's a sed command at the props.conf level.

In your case, the following should work -

SEDCMD-replace = s/,/_/g
0 Karma

javiergn
Super Champion

Alternatively you could use foreach:

| foreach * [eval <<FIELD>>=replace(<<FIELD>>, ",", "_" )]

tuanledang1120
Engager

This works! Thanks a lot!

0 Karma

sundareshr
Legend

Try field=_raw OR you don't need to specify a field. You could just do rex mode=sed "your regex"

0 Karma

tuanledang1120
Engager

I tried this but it didn't work.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...