Hi,
How can we normalize MAC addresses (such as XX:XX:XX:XX:XX:XX or XX-XX-XX-XX-XX-XX) in our environment before implementing the asset and identity in splunk ES, as we are collecting data from workspace.
| rex mode=sed field=mac "s/(..):(..):(..):(..):(..):(..)/\1-\2-\3-\4-\5-\6/g"