Splunk Search

writing rex command in transforms

abhayneilam
Contributor

Hi,

I want to write "rex mode=sed field="DIRECTORY" "s/|/ |/g" in transforms.conf or props.conf so that the replacement happens before importing the file in the splunk . Is it possible please let me know how it could be achieved

Thanks in advance

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You can probably look at the documentation for http://docs.splunk.com/Documentation/Splunk/5.0/admin/Propsconf in particular, SEDCMD.

0 Karma
Get Updates on the Splunk Community!

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...