For instance, I have a log that returns many results and in between different fields I have a \x1 that I would like to replace with a space in order to make it more readable to the user. How can I tell splunk to find all the instances of \x1 and replace them with a space? Any input would be greatly appreciated!
Thanks!
In the search query (search time)
<your base search> | rex mode=sed "s/x1/ /g"
Index time (props.conf)
[yoursourcetype]
SEDCMD-changex1 = s/x1/ /g
In the search query (search time)
<your base search> | rex mode=sed "s/x1/ /g"
Index time (props.conf)
[yoursourcetype]
SEDCMD-changex1 = s/x1/ /g
done thanks!
Glad it helped. Please mark the question answered if everything looks good.
that works great, thanks!
Try '| rex mode=sed
"s/x1/ /g"'.
awesome, that worked great! thanks so much for your help!