Hi guys,
I am trying to run a sedcmd in props.conf and this is regex that I need to replace my internal IPs.
SEDCMD-replace=s/"Device Address"=(\d{1,3}\.\d{1,3}\.\d{1,3})\.(\d{1,3})/"Device Address"=123.234.222.111/g
When I restart Splunk and run a search on Splunk Web, I do not see my IPs masked, they are still the same.
Also I did find similar questions about multiple sed commands in one stanza in same props.conf, but it isn't likely to be working on mine.
Any help will be greatly appreciated.
Thank You!
... View more