|
I am trying to clean up some log data at index time using SEDCMD.
The problem is that nothing is happening. The raw text 'Apple%A0TV' is still occuring and is not getting replaced. Any ideas? |
|
The SEDCMD will not retroactively change the values for data that is already indexed. Have you confirmed that it's not working on new data? Correct. It is not working on new data. Are there any issues with orders of precedence? This is defined on a custom sourcetype which is defined in the forwarding server.
(15 Feb '11, 01:24)
jcbrendsel
The SEDCMD works. Try placing it on your forwarder -- it may not be configured as a light forwarder.
(15 Feb '11, 06:44)
Ron Naken
I meant to say that I tested your SEDCMD, and it works. I can't edit my comment above to change the wording.
(15 Feb '11, 08:53)
Ron Naken
|
|
If this is a light forwarder, SEDCMD will not run there, and must be run on the indexer. Please see http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F for more details I am running SEDCMD on the indexer. But the data is coming from another machine (which is configured as a forwarder).
(15 Feb '11, 08:50)
jcbrendsel
And the forwarder is a light forwarder? Or heavy? And there is no intermediate forwarder?
(15 Feb '11, 22:06)
gkanapathy ♦
|