<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error in Splunk Security Essentials with macro `ut_parse_extended (url, list)` in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399735#M48764</link>
    <description>&lt;P&gt;ut_parse_extended  is in "URL Toolbox". Please install and use APP.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2734/#/details" target="_blank"&gt;https://splunkbase.splunk.com/app/2734/#/details&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 00:04:16 GMT</pubDate>
    <dc:creator>HiroshiSatoh</dc:creator>
    <dc:date>2020-09-30T00:04:16Z</dc:date>
    <item>
      <title>Error in Splunk Security Essentials with macro `ut_parse_extended (url, list)`</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399732#M48761</link>
      <description>&lt;P&gt;Good Morning.&lt;/P&gt;

&lt;P&gt;I am using the "Splunk Security Essentials" add-on and when executing a search, I get an error in the macro &lt;CODE&gt;ut_parse_extended (url, list)&lt;/CODE&gt;. I put the search:&lt;/P&gt;

&lt;P&gt;"index = * sourcetype = pan: threat OR (tag = web tag = proxy) earliest = -20m @ m earliest = -5m @ m | eval list =" mozilla "|&lt;CODE&gt;ut_parse_extended (url, list)&lt;/CODE&gt;| lookup dynamic_dns_lookup domain as ut_domain OUTPUT inlist | search inlist = true | table _time ut_domain inlist bytes * uri "&lt;/P&gt;

&lt;P&gt;And the error:&lt;/P&gt;

&lt;P&gt;"Error in 'SearchParser': The search specifies a macro 'ut_parse_extended' that can not be found. Reasons include: the macro name is misspelled, you do not have" read "permission for the macro, or the macro has not been shared with this application, Click Settings, Advanced search, Search Macros to view macro information. "&lt;/P&gt;

&lt;P&gt;Could you help me? Thank you.&lt;/P&gt;

&lt;P&gt;A greeting.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399732#M48761</guid>
      <dc:creator>socverne</dc:creator>
      <dc:date>2020-09-30T00:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Splunk Security Essentials with macro `ut_parse_extended (url, list)`</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399733#M48762</link>
      <description>&lt;P&gt;Who created this macro(ut_parse_extended )? Please check the permission of this macro.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:02:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399733#M48762</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2020-09-30T00:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Splunk Security Essentials with macro `ut_parse_extended (url, list)`</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399734#M48763</link>
      <description>&lt;P&gt;Thanks for your answer. I have obscured it, and the macro does not exist. With what content can I create it? Thank you.&lt;BR /&gt;
A greeting.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 12:53:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399734#M48763</guid>
      <dc:creator>socverne</dc:creator>
      <dc:date>2019-04-09T12:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Splunk Security Essentials with macro `ut_parse_extended (url, list)`</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399735#M48764</link>
      <description>&lt;P&gt;ut_parse_extended  is in "URL Toolbox". Please install and use APP.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2734/#/details" target="_blank"&gt;https://splunkbase.splunk.com/app/2734/#/details&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:04:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399735#M48764</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2020-09-30T00:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Splunk Security Essentials with macro `ut_parse_extended (url, list)`</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399736#M48765</link>
      <description>&lt;P&gt;"URL Toolbox" is not listed as compatible with Splunk 7.2 or higher. Is there an alternative? Can "URL Toolbox" be manually install without causing issues? Or could the macro be extracted from the install file?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 20:04:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399736#M48765</guid>
      <dc:creator>eliasit</dc:creator>
      <dc:date>2019-07-29T20:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Error in Splunk Security Essentials with macro `ut_parse_extended (url, list)`</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399737#M48766</link>
      <description>&lt;P&gt;Hi socverne,&lt;/P&gt;

&lt;P&gt;The docs of the apps &lt;A href="https://splunkbase.splunk.com/app/3435/#/details"&gt;https://splunkbase.splunk.com/app/3435/#/details&lt;/A&gt; tell you this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; The searches rely on tools included in Splunk platform to perform anomaly detection, such as the URL toolbox to detect Shannon entropy in URLs
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So you need to install &lt;A href="https://splunkbase.splunk.com/app/2734/"&gt;https://splunkbase.splunk.com/app/2734/&lt;/A&gt; to be able to use the macro.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;BUT&lt;/STRONG&gt;, and some greeting to the BOTS 2019 Team here ;), be aware that this macro returns wrong 2nd level domains for some URL's!&lt;/P&gt;

&lt;P&gt;The only way to get around this is to actually use a regex and get the 2nd level domains this way. I ended up with this regex to get the correct 2nd level domains:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; (?&amp;lt;my2ndLevelDomain&amp;gt;[^.]+)\.(?:(?:com|net|org|edu|gov|asn|id|csiro|)\.au|co\.(?:bb|ck|cr|in|id|il|jp|nz|za|kr|th|uk)|[\w\s]{2,})$
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;

&lt;P&gt;PS: @eliasit, yes you still can install the app on Splunk 7.2.x and use it with the above mentioned issues/problems &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 20:37:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-in-Splunk-Security-Essentials-with-macro-ut-parse-extended/m-p/399737#M48766</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2019-07-29T20:37:09Z</dc:date>
    </item>
  </channel>
</rss>

