@isoutamo This worked perfectly! Thank you for your input. Seems the `source` monitor stanza was the way to go. Here is my final configuration for future Splunkers that want to accomplish the same. [source::.../var/log/splunk/splunkd*] SEDCMD-url = s/https?:\/\/www.domain.com\/(.*)/https:\/\/www.domain.com\/XXXX-XXXX-XXXX/g
... View more