How is a remote monitor input distributed to forwarders?
The correct answer is B. in props.conf:
[identity]
SEDCMD-redact_pw = s/password=([^,|/s]+)/ ####REACTED####/g
s/password=([^,|/s]+)/ ####REACTED####/g
The g flag at the end means that the replacement is applied globally, not just to the first match.
Option A is incorrect because it uses the REGEX attribute instead of the SEDCMD attribute. The REGEX attribute is used to extract fields from events, not to modify them.
Option C is incorrect because it uses the transforms.conf file instead of the props.conf file. The transforms.conf file is used to define transformations that can be applied to fields or events, such as lookups, evaluations, or replacements. However, these transformations are applied after indexing, not before.
Option D is incorrect because it uses both the wrong attribute and the wrong file. There is no REGEX-redact_pw attribute in the transforms.conf file.
Adell
6 months agoDarrin
6 months agoRessie
6 months agoDenny
7 months agoLouis
7 months agoLeah
7 months agoIvan
7 months agoJohnson
7 months agoArletta
8 months agoDyan
8 months agoCraig
8 months agoMable
8 months agoLavera
8 months agoGladys
8 months agoWalton
1 year agoBritt
1 year agoShaniqua
1 year agoAngella
11 months agoDolores
12 months agoNana
12 months agoJospeh
1 year agoNieves
12 months agoLucy
1 year agoBrock
1 year agoJohnetta
1 year agoChana
12 months agoJamie
12 months agoIra
12 months agoEloisa
1 year agoGeorgeanna
1 year agoMiesha
1 year agoJesus
1 year ago