<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco eStreamer eNcore Add-on for Splunk does not properly parse the field URL in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454162#M55853</link>
    <description>&lt;P&gt;Hey lakshman239&lt;/P&gt;

&lt;P&gt;i cant see the field url at all, and i don't have any custom props or transform to parse it&lt;BR /&gt;
and yes i can use a rex to remove the value "https", but that's not what i want&lt;BR /&gt;
what i want to see is the field url extracted from the logs&lt;/P&gt;</description>
    <pubDate>Tue, 12 Feb 2019 08:14:11 GMT</pubDate>
    <dc:creator>michaelelizarov</dc:creator>
    <dc:date>2019-02-12T08:14:11Z</dc:date>
    <item>
      <title>Cisco eStreamer eNcore Add-on for Splunk does not properly parse the field URL</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454160#M55851</link>
      <description>&lt;P&gt;My eStreamer system outputs logs with a field called "URL" and the app Cisco eStreamer eNcore Add-on for Splunk&lt;/P&gt;

&lt;P&gt;does not extract it properly&lt;/P&gt;

&lt;P&gt;example:&lt;BR /&gt;
.... url=https:/// ......&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 06:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454160#M55851</guid>
      <dc:creator>michaelelizarov</dc:creator>
      <dc:date>2019-02-06T06:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk does not properly parse the field URL</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454161#M55852</link>
      <description>&lt;P&gt;In our instance, I can see url=&lt;A href="https://outlook.office.365.com"&gt;https://outlook.office.365.com&lt;/A&gt;   and don't see any issues with that? If you don't want &lt;A href="https://," target="test_blank"&gt;https://,&lt;/A&gt; you can use rex to remove them right?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 12:37:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454161#M55852</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-02-06T12:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk does not properly parse the field URL</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454162#M55853</link>
      <description>&lt;P&gt;Hey lakshman239&lt;/P&gt;

&lt;P&gt;i cant see the field url at all, and i don't have any custom props or transform to parse it&lt;BR /&gt;
and yes i can use a rex to remove the value "https", but that's not what i want&lt;BR /&gt;
what i want to see is the field url extracted from the logs&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 08:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454162#M55853</guid>
      <dc:creator>michaelelizarov</dc:creator>
      <dc:date>2019-02-12T08:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk does not properly parse the field URL</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454163#M55854</link>
      <description>&lt;P&gt;which version of TA-eStreamer do you have ? I have 3.5.3 . Also you need to have Splunk_TA_sourcefire add-on for CIM/field extraction. Do you have both of them?  Also, TA-eStreamer/local/props.conf may need to have following if you are using the sourcetypes from the cisco app&lt;BR /&gt;
[cisco:estreamer:data]&lt;BR /&gt;
rename = cisco:sourcefire&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Sourcefire/DataTypes" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/Sourcefire/DataTypes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:15:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454163#M55854</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2020-09-29T23:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk does not properly parse the field URL</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454164#M55855</link>
      <description>&lt;P&gt;Hey lakshman239&lt;/P&gt;

&lt;P&gt;i have this add-on: "&lt;A href="https://splunkbase.splunk.com/app/3662/"&gt;https://splunkbase.splunk.com/app/3662/&lt;/A&gt;"&lt;BR /&gt;
runing in it's latest version: 3.5.4&lt;/P&gt;

&lt;P&gt;and do i have to use this config?&lt;BR /&gt;
[cisco:estreamer:data]&lt;BR /&gt;
rename = cisco:sourcefire&lt;/P&gt;</description>
      <pubDate>Sun, 17 Feb 2019 06:33:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454164#M55855</guid>
      <dc:creator>michaelelizarov</dc:creator>
      <dc:date>2019-02-17T06:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk does not properly parse the field URL</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454165#M55856</link>
      <description>&lt;P&gt;Yes , if you are using cisco:sourcefire sourcetype as part of &lt;A href="https://splunkbase.splunk.com/app/1808/"&gt;https://splunkbase.splunk.com/app/1808/&lt;/A&gt; which has CIM complaince for field extractions&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 22:40:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/454165#M55856</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-02-27T22:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk does not properly parse the field URL</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/553415#M65747</link>
      <description>&lt;P&gt;I modified cisco:estreamer:data : FIELDALIAS-estreamer_url and added url=url.&lt;/P&gt;&lt;P&gt;It only had uri=url.&amp;nbsp; I don't know why url didn't automatically extract but now |table url works.&lt;/P&gt;&lt;P&gt;Splunk 8.x TA-eStreamer 4.6.0&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 21:47:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/553415#M65747</guid>
      <dc:creator>acaruso</dc:creator>
      <dc:date>2021-05-27T21:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco eStreamer eNcore Add-on for Splunk does not properly parse the field URL</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/555069#M65851</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;I too face the same issue where only uri field is being parsed not url.&lt;/P&gt;&lt;P&gt;How can I append in props.conf ? I have the below settings :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FIELDALIAS-estreamer_url = uri as url&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 12:06:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-eStreamer-eNcore-Add-on-for-Splunk-does-not-properly-parse/m-p/555069#M65851</guid>
      <dc:creator>sampathv</dc:creator>
      <dc:date>2021-06-09T12:06:03Z</dc:date>
    </item>
  </channel>
</rss>

