Splunk Search

REGEX - Replace numbers with an asterisk, multiple apperances

KMoryson
Explorer

Hi, I am trying to find a way to replace numbers in strings with an asterisk, if they are concatenated with one, and if not then also with one, using rex field, example:

AA-1234-12-A
BB-1-132-B-1
56-CC-1-345

to be replaced with:

AA-*-*-A
BB-*-*-B-*
*-CC-*-*

I tried multiple sed commands from the internet but they either don't work properly in splunk or do not solve my issue in the exact.

Many thanks

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Does something like this work for you?

| rex mode=sed "s/\d+/*/g"

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Does something like this work for you?

| rex mode=sed "s/\d+/*/g"
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...