# Replacing UID with Username using lookup table

**URL:** <https://community.graylog.org/t/replacing-uid-with-username-using-lookup-table/23385>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [April 13, 2022, 11:58pm UTC](https://community.graylog.org/t/replacing-uid-with-username-using-lookup-table/23385 "2022-04-13T23:58:46Z")\
**Posts on this page:** 1\
**Showing post:** 16

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [April 14, 2022, 8:46pm UTC](https://community.graylog.org/t/replacing-uid-with-username-using-lookup-table/23385/16 "2022-04-14T20:46:31Z")

</div>

I messed up - take out the first “user not found” that deletes the number you are looking for and screws the whole thing up! - I had deleted it in my test but messed up on the one I pasted in!!! so it should be:

```auto
rule "Graylog Web Access User Convert"
when
    contains(to_string($message.message),"UID=")
then
    // create a local to make it slightly less intensive to work with
    let robin = to_string($message.message);
   
    let batman = replace(robin, "1914600003", "steveno");
    let batman = replace(robin, "100100110010011001001", "tad.sherrill");
    let batman = replace(robin, "987324e32874ff32892b2829", "steven.o");

   // changed the number of digits count to be required between 6 and 10 {6,10}
    let batman = regex_replace("(?<=UID\\=)(?>\\d{6,10})",robin,"USER_NOT_FOUND",false);

    set_field("message",batman);
end

```

---

_[View the full topic](https://community.graylog.org/t/replacing-uid-with-username-using-lookup-table/23385)._
