Greetz,
Does anyone know if multiple SEDCMDs are supported at index time in props.conf?
Also, can I implement this search through a regex transform or any other way?
sourcetype="vul:foresight" | rex mode=sed "s/\\\\\\//\\//g" | rex mode=sed "s/\\\n/\n/g" | rex mode=sed "s/<13>.*\.\.\.//g" | rex mode=sed "s/\.\.\..*\n//g" | rex mode=sed "s/^<13>//g"
Thank you.
You can do multiple SEDCMDs for the same sourcetype but not in the same props.conf file I found!
Does anyone have the answer for the second part of his question?
You can do multiple SEDCMDs for the same sourcetype but not in the same props.conf file I found!
Thank you! Brilliant.
Actually you can use multiple SEDCMDs in the same props.conf and for the same sourcetype:
[vul:foresight]
SEDCMD-first = s/\\\//\//g
SEDCMD-second = s/\\n/\n/g
SEDCMD-third = s/<13>.*...//g
etc.