Skip to main content
Version: Next


Replaces the fields matching the given extractors with fixed values.


replace <extractor=operand>...


The replace operator mutates existing fields by providing a new value.

The difference between replace and extend is that replace overwrites existing fields, whereas extend doesn't touch the input.


The assignment consists of an extractor that matches against existing fields and an operand that defines the new field value.

If field does not exist in the input, the operator degenerates to pass. Use the set operator to extend fields that cannot be replaced.


Replace the field the field src_ip with a fixed value:

replace src_ip=

Replace all IP address with a fixed value:

replace :ip=