Hi,
How can I mask the bank balance in splunk? it is showing something like this:
mybal=2426.88,availableBal=2426.88 and I need to replace numbers with #. Please suggest, I am not good in REGEX.
Thanks in advance.
try in props.conf:
[<your sourcetypeName>]
SEDCMD-Anon = s/mybal=\d+\.?\d+/mybal=xxxx/g s/availableBal=\d+\.?\d+/availableBal=xxxx/g
For reference https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata#Anonymize_data_with_a_sed_scr...
Here SEDCMD will mask the data at index time extraction
try in props.conf:
[<your sourcetypeName>]
SEDCMD-Anon = s/mybal=\d+\.?\d+/mybal=xxxx/g s/availableBal=\d+\.?\d+/availableBal=xxxx/g
For reference https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata#Anonymize_data_with_a_sed_scr...
Here SEDCMD will mask the data at index time extraction
thank you it is working....:)
See the docs at http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Anonymizedata
A sed string like "s/(\d+.\d\d)/xxxx.xx/g" should work.
Thanks Rich..it is working for me...:)
Or s/([bB]al\=)(\d+|\d+\.\d+)/\1##.##
.