<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are events in the Splunk Add-on for CyberArk not being extracted? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274522#M32012</link>
    <description>&lt;P&gt;My fields are still not being extracted!&lt;/P&gt;

&lt;P&gt;I replaced the original text with the Answers text:&lt;/P&gt;

&lt;P&gt;[cyberark_epv_cef_cyberark_pta_cef_extract_field_0]&lt;BR /&gt;
REGEX = CEF:\s?(\d+)|((?:\||[^|]))|((?:\||[^|]))|((?:\||[^|]))|((?:\||[^|]))|((?:\||[^|]))|((?:\||[^|]))|[^\s|]+=.*&lt;BR /&gt;
FORMAT = cef_cefVersion::$1 cef_vendor::$2 cef_product::$3 cef_version::$4 cef_signature::$5 cef_name::$6 cef_severity::$7&lt;/P&gt;

&lt;P&gt;in:&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/Splunk_TA_cyberark/default/transforms.conf&lt;/P&gt;

&lt;P&gt;Is there something I'm missing here? any help is greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 01:14:10 GMT</pubDate>
    <dc:creator>ChadLangUAB</dc:creator>
    <dc:date>2020-09-30T01:14:10Z</dc:date>
    <item>
      <title>Why are events in the Splunk Add-on for CyberArk not being extracted?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274517#M32007</link>
      <description>&lt;P&gt;Why are events in the Splunk Add-on for CyberArk not being extracted? &lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2016 13:54:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274517#M32007</guid>
      <dc:creator>stefan1988</dc:creator>
      <dc:date>2016-05-27T13:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events in the Splunk Add-on for CyberArk not being extracted?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274518#M32008</link>
      <description>&lt;P&gt;Splunk Add-on for CyberArk is missing a space in a REGEX causing events not to be extracted. Please adjust the TA into:&lt;BR /&gt;
[cyberark_epv_cef_cyberark_pta_cef_extract_field_0]&lt;BR /&gt;
REGEX = CEF:\s?(\d+)|((?:\||[^|])&lt;EM&gt;)|((?:\||[^|])&lt;/EM&gt;)|((?:\||[^|])&lt;EM&gt;)|((?:\||[^|])&lt;/EM&gt;)|((?:\||[^|])&lt;EM&gt;)|((?:\||[^|])&lt;/EM&gt;)|[^\s|]+=.*&lt;BR /&gt;
FORMAT = cef_cefVersion::$1 cef_vendor::$2 cef_product::$3 cef_version::$4 cef_signature::$5 cef_name::$6 cef_severity::$7&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:49:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274518#M32008</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2020-09-29T09:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events in the Splunk Add-on for CyberArk not being extracted?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274519#M32009</link>
      <description>&lt;P&gt;thanks, there wasn't a way to make you also the answerer, stefan. in the future, please try and post as questions and answers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2016 14:19:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274519#M32009</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2016-05-27T14:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events in the Splunk Add-on for CyberArk not being extracted?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274520#M32010</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;should i change the regex on every node of a distributed installation? Could you please change this in the Addon and release a new version? Would be really usefully.&lt;/P&gt;

&lt;P&gt;regards&lt;BR /&gt;
Andreas&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2016 08:57:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274520#M32010</guid>
      <dc:creator>asartori</dc:creator>
      <dc:date>2016-08-22T08:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events in the Splunk Add-on for CyberArk not being extracted?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274521#M32011</link>
      <description>&lt;P&gt;Hello Andreas, &lt;/P&gt;

&lt;P&gt;You cant put this on your SH, that will do. &lt;/P&gt;

&lt;P&gt;regards&lt;BR /&gt;
Stefan&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2016 12:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274521#M32011</guid>
      <dc:creator>stefan1988</dc:creator>
      <dc:date>2016-11-04T12:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why are events in the Splunk Add-on for CyberArk not being extracted?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274522#M32012</link>
      <description>&lt;P&gt;My fields are still not being extracted!&lt;/P&gt;

&lt;P&gt;I replaced the original text with the Answers text:&lt;/P&gt;

&lt;P&gt;[cyberark_epv_cef_cyberark_pta_cef_extract_field_0]&lt;BR /&gt;
REGEX = CEF:\s?(\d+)|((?:\||[^|]))|((?:\||[^|]))|((?:\||[^|]))|((?:\||[^|]))|((?:\||[^|]))|((?:\||[^|]))|[^\s|]+=.*&lt;BR /&gt;
FORMAT = cef_cefVersion::$1 cef_vendor::$2 cef_product::$3 cef_version::$4 cef_signature::$5 cef_name::$6 cef_severity::$7&lt;/P&gt;

&lt;P&gt;in:&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/Splunk_TA_cyberark/default/transforms.conf&lt;/P&gt;

&lt;P&gt;Is there something I'm missing here? any help is greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:14:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-are-events-in-the-Splunk-Add-on-for-CyberArk-not-being/m-p/274522#M32012</guid>
      <dc:creator>ChadLangUAB</dc:creator>
      <dc:date>2020-09-30T01:14:10Z</dc:date>
    </item>
  </channel>
</rss>

