Will test it out.
I do only have one Splunk server, no forwarder.
Dit not work on my server.
SEDCMD-remove_data = "s/(§4|§r)//g"
It seem to be that the § symbol messes things up.
After removing the " in SEDCMD command, it has no more player, but changed it to playe and have removed the 4 from the time, so it get like this:
I can see in nano that the § shows like a strange character, but ok using cat.