How to filter data with Splunk

  1. Anonymize credit_card and credit_score values:
  1. Splunk processes data in a (linear) pipeline and, naturally there is an order of operations. SEDCMD is applied before TRANSFORMS.
  2. Try to make your regular expressions as specific as possible to minimize processing overhead.
  3. Avoid applying SEDCMD and TRANSFORMS on all data. I.e. limit their application to specific sourcetype, sources or hosts.
  4. Having numerous regular expression make it hard to manage and troubleshoot. Use them only when you need them.

--

--

of streams, flows and floodgates

Love podcasts or audiobooks? Learn on the go with our new app.

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store