Splunk Search

REGEX - Replace numbers with an asterisk, multiple apperances

KMoryson
Explorer

Hi, I am trying to find a way to replace numbers in strings with an asterisk, if they are concatenated with one, and if not then also with one, using rex field, example:

AA-1234-12-A
BB-1-132-B-1
56-CC-1-345

to be replaced with:

AA-*-*-A
BB-*-*-B-*
*-CC-*-*

I tried multiple sed commands from the internet but they either don't work properly in splunk or do not solve my issue in the exact.

Many thanks

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Does something like this work for you?

| rex mode=sed "s/\d+/*/g"

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Does something like this work for you?

| rex mode=sed "s/\d+/*/g"
Get Updates on the Splunk Community!

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...