I am trying to clean up some log data at index time using SEDCMD.
The problem is that nothing is happening. The raw text 'Apple%A0TV' is still occuring and is not getting replaced.
If this is a light forwarder, SEDCMD will not run there, and must be run on the indexer. Please see http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F for more details
answered 15 Feb '11, 01:32