Splunk's | rex mode=sed equivalent in Sumo


1 comment

  • Official comment
    Ryan Johnson

    Hi Antony,

    I have some good news! We recently released regular expression support in our replace operator which can do exactly what you've detailed. Give the following a try:

    | replace (x, /d{2,}/, "ID") AS x

    More details can be found in our online documentation here (LINK)

    I hope this helps!

    Comment actions Permalink

Please sign in to leave a comment.