Splunk Search

SEDCMD: How to change the format of my data collection?

khyoung7410
Communicator

Hi

The format of my data collection is as follows.

There are a total of 29 letters and numbers.

* Sample data
D0064659949080052811436122722

Can I replace the 13th to 25th digit with a space in these data?

This is the type of data I want:

<pre>D00646599490             2722</pre>

Thank you

Tags (2)
0 Karma
1 Solution

FrankVl
Ultra Champion

Sure, I think the following should work: SEDCMD = s/(.{12}).{13}(.*)/\1 \2/g

View solution in original post

0 Karma

FrankVl
Ultra Champion

Sure, I think the following should work: SEDCMD = s/(.{12}).{13}(.*)/\1 \2/g

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...