My developers are adding dashes ---
in their logs all over. Sometimes 1.. sometimes 10 dashes. Makes them look really ugly in Splunk. Hoping to remove them using SEDCMD. Any idea why this isn't working?
SEDCMD-fixdash=s/[-]*/-/g
thanks,
-Daniel
If they are your developers, make them stop doing that stuff and log JSON instead. 😉
Try SEDCMD-fixdash=s/-+/-/g
Dash is not a RegEx special character, so no character class needed. '+' means 'one or more'.