Splunk's | rex mode=sed equivalent in Sumo

Comments

1 comment

  • Official comment
    Avatar
    Ryan Johnson

    Hi Antony,

    I have some good news! We recently released regular expression support in our replace operator which can do exactly what you've detailed. Give the following a try:

    | replace (x, /d{2,}/, "ID") AS x

    More details can be found in our online documentation here (LINK)

    I hope this helps!

Please sign in to leave a comment.