<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Field Extraction Using Tranforms Configration in Security</title>
    <link>https://community.splunk.com/t5/Security/Field-Extraction-Using-Tranforms-Configration/m-p/669104#M17392</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have some issues to perform field extractions using transform configuration. It's not giving field value pairs as expected. Sample events and configuration files are given below. Some non-uniformities within the events are also marked in Bold. Any recommendations will be highly appreciated. Thank you so much.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Configuration Files&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[mypropfConf]&lt;/P&gt;&lt;P&gt;REPORT-mytranforms=myTransConf&lt;/P&gt;&lt;P&gt;[myTransConf]&lt;BR /&gt;REGEX = ([^"]+?):'([^"]+?)'&lt;BR /&gt;FORMAT = $1::$2&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sample Events&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2023-11-15T18:56:29.098Z OTESTN097MA4515620 TEST&lt;STRONG&gt;user20248:&lt;/STRONG&gt; UserID: '90A', UserType: 'TempEMP', System: 'TEST', UAT: 'UTA-True', EventType: 'TEST', EventID: 'Lookup', Subject: 'A5367817222', Scode: '' &lt;STRONG&gt;EventStatus: 0&lt;/STRONG&gt;, TimeStamp: '2023-11-03T15:56:29.099Z', Device: 'OTESTN097MA4513020', Msg: 'lookup ok', var: 'Sec'&lt;/P&gt;&lt;P&gt;2023-11-15T18:56:29.021Z OTESTN097MB7513020 TESTuser20249: UserID: '95B', UserType: 'TempEMP', System: 'TEST', UAT: 'UTA-True', EventType: 'TEST', EventID: 'Lookup', Subject: 'A516670222', Scode: '' EventStatus: 0, TimeStamp: '2023-11-03T15:56:29.099Z', Device: 'OTESTN097MA4513020', Msg: 'lookup ok', var: 'tec'&lt;/P&gt;&lt;P&gt;2023-11-15T18:56:29.009Z OTESTN097MB9513020 TESTuser20248: UserID: '95A', UserType: 'TempEMP', System: 'TEST', UAT: 'UTA-True', EventType: 'TEST', EventID: 'Lookup', Subject: 'A546610222', Scode: '' EventStatus: 0, TimeStamp: '2023-11-03T15:56:29.099Z', Device: 'OTESTN097MA4513020', Msg: 'lookup ok', var: 'test'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 19 Nov 2023 03:11:06 GMT</pubDate>
    <dc:creator>SplunkDash</dc:creator>
    <dc:date>2023-11-19T03:11:06Z</dc:date>
    <item>
      <title>Field Extraction Using Tranforms Configration</title>
      <link>https://community.splunk.com/t5/Security/Field-Extraction-Using-Tranforms-Configration/m-p/669104#M17392</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have some issues to perform field extractions using transform configuration. It's not giving field value pairs as expected. Sample events and configuration files are given below. Some non-uniformities within the events are also marked in Bold. Any recommendations will be highly appreciated. Thank you so much.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Configuration Files&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[mypropfConf]&lt;/P&gt;&lt;P&gt;REPORT-mytranforms=myTransConf&lt;/P&gt;&lt;P&gt;[myTransConf]&lt;BR /&gt;REGEX = ([^"]+?):'([^"]+?)'&lt;BR /&gt;FORMAT = $1::$2&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sample Events&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2023-11-15T18:56:29.098Z OTESTN097MA4515620 TEST&lt;STRONG&gt;user20248:&lt;/STRONG&gt; UserID: '90A', UserType: 'TempEMP', System: 'TEST', UAT: 'UTA-True', EventType: 'TEST', EventID: 'Lookup', Subject: 'A5367817222', Scode: '' &lt;STRONG&gt;EventStatus: 0&lt;/STRONG&gt;, TimeStamp: '2023-11-03T15:56:29.099Z', Device: 'OTESTN097MA4513020', Msg: 'lookup ok', var: 'Sec'&lt;/P&gt;&lt;P&gt;2023-11-15T18:56:29.021Z OTESTN097MB7513020 TESTuser20249: UserID: '95B', UserType: 'TempEMP', System: 'TEST', UAT: 'UTA-True', EventType: 'TEST', EventID: 'Lookup', Subject: 'A516670222', Scode: '' EventStatus: 0, TimeStamp: '2023-11-03T15:56:29.099Z', Device: 'OTESTN097MA4513020', Msg: 'lookup ok', var: 'tec'&lt;/P&gt;&lt;P&gt;2023-11-15T18:56:29.009Z OTESTN097MB9513020 TESTuser20248: UserID: '95A', UserType: 'TempEMP', System: 'TEST', UAT: 'UTA-True', EventType: 'TEST', EventID: 'Lookup', Subject: 'A546610222', Scode: '' EventStatus: 0, TimeStamp: '2023-11-03T15:56:29.099Z', Device: 'OTESTN097MA4513020', Msg: 'lookup ok', var: 'test'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Nov 2023 03:11:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Field-Extraction-Using-Tranforms-Configration/m-p/669104#M17392</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2023-11-19T03:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction Using Tranforms Configration</title>
      <link>https://community.splunk.com/t5/Security/Field-Extraction-Using-Tranforms-Configration/m-p/669108#M17393</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you can use REPORT i you have a list of fields separated by comma or another char.&lt;/P&gt;&lt;P&gt;In your case I'd use a regex in props.conf&amp;nbsp; like the following&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;EXTRACT-your_sourcetype = ^(?&amp;lt;timestamp&amp;gt;\d+-\d+-\d+T\d+:\d+:\d+\.\d+\w)\s+(?&amp;lt;host&amp;gt;[^ ]+)\s+(?&amp;lt;user&amp;gt;[^:]+):\s+UserID:\s+\'(?&amp;lt;UserID&amp;gt;[^\']+)\',\s+UserType:\s+\'(?&amp;lt;UserType&amp;gt;[^\']+)\',\s+System:\s+\'(?&amp;lt;System&amp;gt;[^\']+)\',\s+UAT:\s+\'(?&amp;lt;UAT&amp;gt;[^\']+)\',\s+EventType:\s+\'(?&amp;lt;EventType&amp;gt;[^\']+)\',\s+EventID:\s+\'(?&amp;lt;EventID&amp;gt;[^\']+)\',\s+Subject:\s+\'(?&amp;lt;Subject&amp;gt;[^\']+)\',\s+Scode:\s+\'(?&amp;lt;Scode&amp;gt;[^\']*)\'\s+EventStatus:\s+(?&amp;lt;EventStatus&amp;gt;\d*),\s+TimeStamp:\s*\'(?&amp;lt;TimeStamp&amp;gt;[^\']*)\',\s+Device:\s*\'(?&amp;lt;Device&amp;gt;[^\']*)\',\s+Msg:\s*\'(?&amp;lt;Msg&amp;gt;[^\']*)\',\s+var:\s*\'(?&amp;lt;var&amp;gt;[^\']*)\'&lt;/LI-CODE&gt;&lt;P&gt;You can test the regex at&amp;nbsp;&lt;A href="https://regex101.com/r/iQZi9K/1" target="_blank"&gt;https://regex101.com/r/iQZi9K/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Guseppe&lt;/P&gt;</description>
      <pubDate>Sun, 19 Nov 2023 06:59:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Field-Extraction-Using-Tranforms-Configration/m-p/669108#M17393</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-19T06:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction Using Tranforms Configration</title>
      <link>https://community.splunk.com/t5/Security/Field-Extraction-Using-Tranforms-Configration/m-p/669112#M17394</link>
      <description>&lt;P&gt;I'm not sure if there was any modification to the copy-pasted config and/or events but your regex doesn't allow for spaces between the semicolon after the key name and the value.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Nov 2023 07:56:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Field-Extraction-Using-Tranforms-Configration/m-p/669112#M17394</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-19T07:56:44Z</dc:date>
    </item>
  </channel>
</rss>

