Splunk Search

SED command on props


Good Day all. I am trying to replace a last name using SED command on my props.
my data looks like below.
asdfa asdf first last asdf
asdf asdf first last asdf
asdf asdf first last asdf

My props looks like below


When i upload the data into splunk my data is looking like below

first XXXXXXXX asdf
first XXXXXXXX asdf
first XXXXXXXX asdf

So basically it replaced the entire data before the pattern with the capture group and the modification which is the XXXX. i could capture the whole data as a capture group and replace them but i am looking for options where i can just replace the capture group with the modification.
so that my data looks like

asdf asdf first XXXXX asdf
Tags (3)
0 Karma


There are several things wrong with the SEDCMD. Try:


That should do what you want.

0 Karma

Ultra Champion

@ranjitbrhm1 as mentioned on Slack, if it is indeed always the 4th word that needs to be masked, this should do the trick.

0 Karma

Splunk Employee
Splunk Employee

Can you post a better example of your data, your sample tells us nothing about the data and what you are attempting to replace. If we could see more, we could suggest a better SED expression for you to use.

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...