<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multi Line Field Extraction for XML in Security</title>
    <link>https://community.splunk.com/t5/Security/Multi-Line-Field-Extraction-for-XML/m-p/671102#M17481</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have some issues to perform multi-line field extraction for XML, my in-line extraction is not getting any result; sample events and my in-line extraction are provided below. Any help would be appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sample Events:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Event&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;ID&amp;gt;0123011&amp;lt;/ID&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Time&amp;gt;2023-10-28T05:22:37.97011&amp;lt;/Time&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Application_Name&amp;gt;Test&amp;lt;/Application_Name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Host_Name&amp;gt;VS0SMADBEFT&amp;lt;/Host_Name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/Event&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Event&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;ID&amp;gt;01232113&amp;lt;/ID&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Time&amp;gt;2023-10-28T05:22:37.99011&amp;lt;/Time&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Application_Name&amp;gt;Test&amp;lt;/Application_Name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Host_Name&amp;gt;VS0SMADBEFT&amp;lt;/Host_Name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/Event&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In Line Extraction I Used&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;ID&amp;gt;(?&amp;lt;ID&amp;gt;[^&amp;lt;]+)&amp;lt;\/ID&amp;gt;([\r\n]*)&amp;lt;Time&amp;gt;(?&amp;lt;Time&amp;gt;[^&amp;lt;]+)&amp;lt;/Time&amp;gt;([\r\n]*)&amp;lt;Application_Name&amp;gt;(?&amp;lt;Application_Name&amp;gt;[^&amp;lt;]+)&amp;lt;/Application_Name&amp;gt;([\r\n]*)&amp;lt;Host_Name&amp;gt;(?&amp;lt;Host_Name&amp;gt;[^&amp;lt;]+)&amp;lt;/Host_Name&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Dec 2023 04:44:40 GMT</pubDate>
    <dc:creator>SplunkDash</dc:creator>
    <dc:date>2023-12-07T04:44:40Z</dc:date>
    <item>
      <title>Multi Line Field Extraction for XML</title>
      <link>https://community.splunk.com/t5/Security/Multi-Line-Field-Extraction-for-XML/m-p/671102#M17481</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have some issues to perform multi-line field extraction for XML, my in-line extraction is not getting any result; sample events and my in-line extraction are provided below. Any help would be appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sample Events:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Event&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;ID&amp;gt;0123011&amp;lt;/ID&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Time&amp;gt;2023-10-28T05:22:37.97011&amp;lt;/Time&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Application_Name&amp;gt;Test&amp;lt;/Application_Name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Host_Name&amp;gt;VS0SMADBEFT&amp;lt;/Host_Name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/Event&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Event&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;ID&amp;gt;01232113&amp;lt;/ID&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Time&amp;gt;2023-10-28T05:22:37.99011&amp;lt;/Time&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Application_Name&amp;gt;Test&amp;lt;/Application_Name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Host_Name&amp;gt;VS0SMADBEFT&amp;lt;/Host_Name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/Event&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In Line Extraction I Used&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;ID&amp;gt;(?&amp;lt;ID&amp;gt;[^&amp;lt;]+)&amp;lt;\/ID&amp;gt;([\r\n]*)&amp;lt;Time&amp;gt;(?&amp;lt;Time&amp;gt;[^&amp;lt;]+)&amp;lt;/Time&amp;gt;([\r\n]*)&amp;lt;Application_Name&amp;gt;(?&amp;lt;Application_Name&amp;gt;[^&amp;lt;]+)&amp;lt;/Application_Name&amp;gt;([\r\n]*)&amp;lt;Host_Name&amp;gt;(?&amp;lt;Host_Name&amp;gt;[^&amp;lt;]+)&amp;lt;/Host_Name&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 04:44:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Multi-Line-Field-Extraction-for-XML/m-p/671102#M17481</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2023-12-07T04:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Multi Line Field Extraction for XML</title>
      <link>https://community.splunk.com/t5/Security/Multi-Line-Field-Extraction-for-XML/m-p/671116#M17482</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/Latest/Admin/Propsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/Latest/Admin/Propsconf&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;* dotall (?s) and multi-line (?m) modifiers are added in front of the regex.
  So internally, the regex becomes (?ms)&amp;lt;regex&amp;gt;.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;So if your regex doesn't match, there might be something not 100% OK with it. It almost checks out on regex101 but it warns about possible necessity of escaping the included slashes. So I'd start with verifying that.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 07:59:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Multi-Line-Field-Extraction-for-XML/m-p/671116#M17482</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-07T07:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Multi Line Field Extraction for XML</title>
      <link>https://community.splunk.com/t5/Security/Multi-Line-Field-Extraction-for-XML/m-p/671153#M17483</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you so much for your quick response. However, no changes.&lt;/P&gt;
&lt;P&gt;I was trying to use props and transforms conf files, but not working as well&lt;/P&gt;
&lt;P&gt;My props transforms&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[myprops]

REPORT-mytrans_fields=mytrans_fields

[mytrans_fields]

REGEX=\&amp;lt;(\w+[^\n\/\&amp;gt;]+)\/?\&amp;gt;([^\&amp;lt;\n][^\&amp;lt;]*)

FORMAT=$1::$2

DEST_KEY=_raw&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any recommendations?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 15:13:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Multi-Line-Field-Extraction-for-XML/m-p/671153#M17483</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2023-12-07T15:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: Multi Line Field Extraction for XML</title>
      <link>https://community.splunk.com/t5/Security/Multi-Line-Field-Extraction-for-XML/m-p/671176#M17484</link>
      <description>&lt;P&gt;To be fully honest, if your data is a well-formed XML, I'd just go for&lt;/P&gt;&lt;PRE&gt;KV_MODE=xml&lt;/PRE&gt;</description>
      <pubDate>Thu, 07 Dec 2023 18:01:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Multi-Line-Field-Extraction-for-XML/m-p/671176#M17484</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-12-07T18:01:30Z</dc:date>
    </item>
  </channel>
</rss>

