<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SEP 14.2 RU1 log format change in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454521#M55914</link>
    <description>&lt;P&gt;Hi Everyone,&lt;BR /&gt;
We are using the SEP 14.2.1 (14.2 RU1 MP1) build 4815 (14.2.4815.1101)&lt;BR /&gt;
Installed the last Symantec Add-On, and since the Risk were not correctly tagged, I have modified the regex like this :&lt;/P&gt;

&lt;P&gt;(you can put it on local/transforms.conf)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[field_extraction_for_agt_risk]
### Modified Regex, removed unknown tag that brokes the regex, and moved certificates tags to the end to be recognized.
REGEX = (?i)(?:[[sep_file_prefix]]),\s*(?&amp;lt;Risk_Action&amp;gt;[[sep_file_field]]),\s*(?:IP\sAddress:\s*(?&amp;lt;IP_Address&amp;gt;[[sep_file_field]]))?,\s*(?:Computer\sname:\s*(?&amp;lt;Computer_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Source:\s*(?&amp;lt;Source&amp;gt;[[sep_file_field]]))?,\s*(?:Risk\sname:\s*(?&amp;lt;Risk_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?&amp;lt;Occurrences&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;file_path&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Description&amp;gt;[[sep_file_field]]),\s*(?:Actual\saction:\s*(?&amp;lt;vendor_action&amp;gt;[[sep_file_field]]))?,\s*(?:Requested\saction:\s*(?&amp;lt;Requested_Action&amp;gt;[[sep_file_field]]))?,\s*(?:Secondary\saction:\s*(?&amp;lt;Secondary_Action&amp;gt;[[sep_file_field]]))?,\s*(?:Event\stime:\s*(?&amp;lt;Event_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Inserted:\s*(?&amp;lt;Event_Insert_Time&amp;gt;[[sep_file_field]]))?,\s*(?:End:\s*(?&amp;lt;End_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Last\supdate\stime:\s*(?&amp;lt;Last_Update_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Domain:\s*(?&amp;lt;Domain_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Group:\s*(?&amp;lt;Group_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Server:\s*(?&amp;lt;Server_Name&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;user&amp;gt;[[sep_file_field]]),\s*(?:Source\scomputer:\s*(?&amp;lt;Source_Computer_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Source\sIP:\s*(?&amp;lt;Source_Computer_IP&amp;gt;[[sep_file_field]]))?,\s*(?:Disposition:\s*(?&amp;lt;Disposition&amp;gt;[[sep_file_field]]))?,\s*(?:Download\ssite:\s*(?&amp;lt;Download_Site&amp;gt;[[sep_file_field]]))?,\s*(?:Web\sdomain:\s*(?&amp;lt;Web_Domain&amp;gt;.*))?,\s*(?:Downloaded\sby:\s*(?&amp;lt;Downloaded_By&amp;gt;[[sep_file_field]]))?,\s*(?:Prevalence:\s*(?&amp;lt;Prevalence&amp;gt;[[sep_file_field]]))?,\s*(?:Confidence:\s*(?&amp;lt;Confidence&amp;gt;[[sep_file_field]]))?,\s*(?:URL\sTracking\sStatus:\s*(?&amp;lt;URL_Tracking_Status&amp;gt;[[sep_file_field]]))?,\s*(?:First\sseen:\s*(?&amp;lt;First_Seen&amp;gt;[[sep_file_field]]))?,\s*(?:Sensitivity:\s*(?&amp;lt;Sensitivity&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;Reason_For_White_Listing&amp;gt;[[sep_file_field]]),\s*(?:Application\shash:\s*(?&amp;lt;Application_Hash&amp;gt;[[sep_file_field]]))?,\s*(?:Hash\stype:\s*(?&amp;lt;Hash_Type&amp;gt;[[sep_file_field]]))?,\s*(?:Company\sname:\s*(?&amp;lt;Company_Name&amp;gt;.*))?,\s*(?:Application\sname:\s(?&amp;lt;Application_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Application\sversion:\s*(?P&amp;lt;Application_Version&amp;gt;.*))?,\s*(?:Application\stype:\s*(?&amp;lt;Application_Type&amp;gt;[[sep_file_field]]))?,\s*(?:File\ssize\s\(bytes\):\s*(?&amp;lt;File_Size&amp;gt;[[sep_file_field]]))?(?:,\s*Category\sset:\s*(?&amp;lt;Category_Set&amp;gt;[[sep_file_field]]),\s*Category\stype:\s*(?&amp;lt;Category_Type&amp;gt;[[sep_file_field]]))?,?\s*(?:Location:\s*(?&amp;lt;Location&amp;gt;[[sep_file_field]]))?,?\s*(?:Intensive\sProtection\sLevel:\s*(?&amp;lt;Intensive_Protection_Level&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sissuer:\s*(?&amp;lt;Certificate_Issuer&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\ssigner:\s*(?&amp;lt;Certificate_Signer&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sthumbprint:\s*(?&amp;lt;Certificate_Thumbprint&amp;gt;[[sep_file_field]]))?,?\s*(?:Signing\stimestamp:\s*(?&amp;lt;Signing_Timestamp&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sserial\snumber:\s*(?&amp;lt;Certificate_Serial_Number&amp;gt;[[sep_file_field]]))?

[field_extraction_for_agt_proactive]
### Modified Regex, moved certificate tags to the end like the agt_risk one.
REGEX = (?i)(?:[[sep_file_prefix]]),\s*(?&amp;lt;Risk_Action&amp;gt;[[sep_file_field]]),\s*(?:Computer\sname:\s*(?&amp;lt;Computer_Name&amp;gt;[[sep_file_field]]))?,?\s*(?:IP\sAddress:\s*(?&amp;lt;IP_Address&amp;gt;[[sep_file_field]]))?,\s*(?:Detection\stype:\s*(?&amp;lt;Detection_Type&amp;gt;[[sep_file_field]]))?,\s*(?:First\sseen:\s*(?&amp;lt;First_Seen&amp;gt;[[sep_file_field]]))?,\s*(?:Application\sname:\s*(?&amp;lt;Application_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Application\stype:\s*(?&amp;lt;Application_Type&amp;gt;[[sep_file_field]]))?,\s*(?:Application\sversion:\s*(?&amp;lt;Application_Version&amp;gt;[[sep_file_field]]))?,\s*(?:Hash\stype:\s*(?&amp;lt;Hash_Type&amp;gt;[[sep_file_field]]))?,\s*(?:Application\shash:\s*(?&amp;lt;Application_Hash&amp;gt;[[sep_file_field]]))?,\s*(?:Company\sname:\s*(?&amp;lt;Company_Name&amp;gt;.*))?,\s*(?:File\ssize\s\(bytes\):\s*(?&amp;lt;File_Size&amp;gt;[[sep_file_field]]))?,\s*(?:Sensitivity:\s*(?&amp;lt;Sensitivity&amp;gt;[[sep_file_field]]))?,\s*(?:Detection\sscore:\s*(?&amp;lt;Detection_Score&amp;gt;[[sep_file_field]]))?,\s*(?:COH\sEngine\sVersion:\s*(?&amp;lt;COH_Engine_Version&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;Submission_Recommendation&amp;gt;[[sep_file_field]]),\s*(?:Permitted\sapplication\sreason:\s*(?&amp;lt;Permitted_Application_Reason&amp;gt;[[sep_file_field]]))?,\s*(?:Disposition:\s*(?&amp;lt;Disposition&amp;gt;[[sep_file_field]]))?,\s*(?:Download\ssite:\s*(?&amp;lt;Download_Site&amp;gt;[[sep_file_field]]))?,\s*(?:Web\sdomain:\s*(?&amp;lt;Web_Domain&amp;gt;.*))?,\s*(?:Downloaded\sby:\s*(?&amp;lt;Downloaded_By&amp;gt;[[sep_file_field]]))?,\s*(?:Prevalence:\s*(?&amp;lt;Prevalence&amp;gt;[[sep_file_field]]))?,\s*(?:Confidence:\s*(?&amp;lt;Confidence&amp;gt;[[sep_file_field]]))?,\s*(?:URL\sTracking\sStatus:\s*(?&amp;lt;URL_Tracking_Status&amp;gt;[[sep_file_field]]))?,\s*(?:Risk\sLevel:\s*(?&amp;lt;Risk_Level&amp;gt;[[sep_file_field]]))?,?\s*(?:Risk\stype:\s*(?&amp;lt;Risk_Type&amp;gt;[[sep_file_field]]))?,?\s*(?:Detection\sSource:\s*(?&amp;lt;Detection_Source&amp;gt;[[sep_file_field]]))?,\s*(?:Source:\s*(?&amp;lt;Source&amp;gt;[[sep_file_field]]))?,\s*(?:Risk\sname:\s*(?&amp;lt;Risk_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?&amp;lt;Occurrences&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;file_path&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Description&amp;gt;[[sep_file_field]]),\s*(?:Actual\saction:\s*(?&amp;lt;vendor_action&amp;gt;[[sep_file_field]]))?,\s*(?:Requested\saction:\s*(?&amp;lt;Requested_Action&amp;gt;[[sep_file_field]]))?,\s*(?:Secondary\saction:\s*(?&amp;lt;Secondary_Action&amp;gt;[[sep_file_field]]))?,\s*(?:Event\stime:\s*(?&amp;lt;Event_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Inserted:\s*(?&amp;lt;Event_Insert_Time&amp;gt;[[sep_file_field]]))?,\s*(?:End:\s*(?&amp;lt;End_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Domain:\s*(?&amp;lt;Domain_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Group:\s*(?&amp;lt;Group_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Server:\s*(?&amp;lt;Server_Name&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;user&amp;gt;[[sep_file_field]]),\s*(?:Source\scomputer:\s*(?&amp;lt;Source_Computer_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Source\sIP:\s*(?&amp;lt;Source_Computer_IP&amp;gt;[[sep_file_field]]))?,?\s*(?:Intensive\sProtection\sLevel:\s*(?&amp;lt;Intensive_Protection_Level&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sissuer:\s*(?&amp;lt;Certificate_Issuer&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\ssigner:\s*(?&amp;lt;Certificate_Signer&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sthumbprint:\s*(?&amp;lt;Certificate_Thumbprint&amp;gt;[[sep_file_field]]))?,?\s*(?:Signing\stimestamp:\s*(?&amp;lt;Signing_Timestamp&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sserial\snumber:\s*(?&amp;lt;Certificate_Serial_Number&amp;gt;[[sep_file_field]]))?
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this works for you.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Dec 2019 13:57:59 GMT</pubDate>
    <dc:creator>cascompany</dc:creator>
    <dc:date>2019-12-02T13:57:59Z</dc:date>
    <item>
      <title>SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454500#M55893</link>
      <description>&lt;P&gt;Symantec slightly change the log format for 14.2 RU1... add these to transforms.conf in /local and you'll be good to go.&lt;/P&gt;

&lt;P&gt;[field_extraction_for_traffic]&lt;BR /&gt;
REGEX = (?i)(?:[[sep_file_prefix]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?:Local Host:\s*(?[[sep_file_field]]))?,\s*(?:Local Port:\s*(?[[sep_file_field]]))?,\s*(?:Local Host MAC:\s*(?[[sep_file_field]]))?,\s*(?:Remote Host IP:\s*(?[[sep_file_field]]))?,\s*(?:Remote Host Name:\s*(?[[sep_file_field]]))?,\s*(?:Remote Port:\s*(?[[sep_file_field]]))?,\s*(?:Remote Host MAC:\s*(?[[sep_file_field]]))?,\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?:Begin:\s*(?[[sep_file_field]]))?,\s*(?:End:\s*(?[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?[[sep_file_field]]))?,\s*(?:Application:\s*(?[[sep_file_field]]))?,\s*(?:Rule:\s*(?[[sep_file_field]]))?,\s*(?:Location:\s*(?[[sep_file_field]]))?,\s*(?:User:\s*(?[[sep_file_field]]))?,\s*(?:Domain:\s*(?[[sep_file_field]]))?,\s*(?:Action:\s*(?[[sep_file_field]]))?,\s*(?:SHA-256:\s*(?[[sep_file_field]]))?,\s*(?:MD-5:\s*(?[[sep_file_field]]))?&lt;/P&gt;

&lt;P&gt;[field_extraction_for_agt_security]&lt;BR /&gt;
REGEX = (?i)(?:[[sep_file_prefix]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?:Event Description:\s*(?[[sep_file_field]])),\s*(?:Local:\s*(?[[sep_file_field]]))?,\s*(?:Local Host MAC:\s*(?[[sep_file_field]]))?,\s*(?:Remote Host Name:\s*(?[[sep_file_field]]))?,\s*(?:Remote Host IP:\s*(?[[sep_file_field]]))?,\s*(?:Remote Host MAC:\s*(?[[sep_file_field]]))?,\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?:Begin:\s*(?[[sep_file_field]]))?,\s*(?:End:\s*(?[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?[[sep_file_field]]))?,\s*(?:Application:\s*(?[[sep_file_field]]))?,\s*(?:Location:\s*(?[[sep_file_field]]))?,\s*(?:User:\s*(?[[sep_file_field]])),\s*(?:Domain:\s*(?[[sep_file_field]]))?,\s*(?:Local\sPort\s*(?[[sep_file_field]]))?,\s*(?:Remote\sPort\s*(?[[sep_file_field]]))?,\s*(?:CIDS\sSignature\sID:\s*(?[[sep_file_field]]))?,\s*(?:CIDS\sSignature\sstring:\s*(?[[sep_file_field]]))?,\s*(?:CIDS\sSignature\sSubID:\s*(?[[sep_file_field]]))?,\s*(?:Intrusion\sURL:\s*(?[[sep_file_field]]))?,\s*(?:Intrusion\sPayload\sURL:\s*(?[[sep_file_field]]))?,?\s*(?:SHA-256:\s*(?[[sep_file_field]]))?,?\s*(?:MD-5:\s*(?[[sep_file_field]]))?&lt;/P&gt;

&lt;P&gt;[field_extraction_for_agt_risk]&lt;BR /&gt;
REGEX = (?i)(?:[[sep_file_prefix]]),\s*(?[[sep_file_field]]),\s*(?:IP\sAddress:\s*(?[[sep_file_field]]))?,\s*(?:Computer\sname:\s*(?[^,']&lt;EM&gt;'[^']&lt;/EM&gt;'|[^,"]&lt;EM&gt;"[^"]&lt;/EM&gt;|[^,]&lt;EM&gt;))?,\s&lt;/EM&gt;(?:Source:\s*(?[[sep_file_field]]))?,\s*(?:Risk\sname:\s*(?[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?[[sep_file_field]]))?,\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?:Actual\saction:\s*(?[[sep_file_field]]))?,\s*(?:Requested\saction:\s*(?[[sep_file_field]]))?,\s*(?:Secondary\saction:\s*(?[[sep_file_field]]))?,\s*(?:Event\stime:\s*(?[[sep_file_field]]))?,s*(?:Inserted:\s*(?[[sep_file_field]]))?,\s*(?:End:\s*(?[[sep_file_field]]))?,\s*(?:Last\supdate\stime:\s*(?[[sep_file_field]]))?,\s*(?:Domain:\s*(?[[sep_file_field]]))?,\s*(?:Group:\s*(?[[sep_file_field]]))?,\s*(?:Server:\s*(?[[sep_file_field]]))?,\s*(?:User:\s*(?[[sep_file_field]])),\s*(?:Source\scomputer:\s*(?[[sep_file_field]]))?,\s*(?:Source\sIP:\s*(?[[sep_file_field]]))?,\s*(?:Disposition:\s*(?[[sep_file_field]]))?,\s*(?:Download\ssite:\s*(?[[sep_file_field]]))?,\s*(?:Web\sdomain:\s*(?.&lt;EM&gt;))?,\s&lt;/EM&gt;(?:Downloaded\sby:\s*(?[[sep_file_field]]))?,\s*(?:Prevalence:\s*(?[[sep_file_field]]))?,\s*(?:Confidence:\s*(?[[sep_file_field]]))?,\s*(?:URL\sTracking\sStatus:\s*(?[[sep_file_field]]))?,\s*(?:First\sseen:\s*(?[[sep_file_field]]))?,\s*(?:Sensitivity:\s*(?[[sep_file_field]]))?,\s*(?[[sep_file_field]]),\s*(?:Application\shash:\s*(?[[sep_file_field]]))?,\s*(?:Hash\stype:\s*(?[[sep_file_field]]))?,\s*(?:Company\sname:\s*(?.&lt;EM&gt;))?,\s&lt;/EM&gt;(?:Application\sname:\s(?[[sep_file_field]]))?,\s*(?:Application\sversion:\s*(?P.&lt;EM&gt;))?,\s&lt;/EM&gt;(?:Application\stype:\s*(?[[sep_file_field]]))?,\s*(?:File\ssize\s(bytes):\s*(?[[sep_file_field]]))?(?:,\s*Category\sset:\s*(?[[sep_file_field]]),\s*Category\stype:\s*(?[[sep_file_field]]))?,?\s*(?:Location:\s*(?[[sep_file_field]]))?,?\s*(?:Intensive\sProtection\sLevel:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\sissuer:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\ssigner:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\sthumbprint:\s*(?[[sep_file_field]]))?,?\s*(?:Signing\stimestamp:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\sserial\snumber:\s*(?[[sep_file_field]]))?&lt;/P&gt;

&lt;P&gt;[field_extraction_for_agt_behavior]&lt;BR /&gt;
REGEX = ^(?i)(?:[[sep_file_prefix]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),?\s*(?[[sep_file_field]])?,\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?:Begin:\s*(?[[sep_file_field]]))?,\s*(?:End:\s*(?[[sep_file_field]]))?,\s*(?:Rule:\s*(?[[sep_file_field]])),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?:User:\s*(?[[sep_file_field]])),\s*(?:Domain:\s*(?[[sep_file_field]]))?,\s*(?:Action\sType:\s*(?[[sep_file_field]]))?(?:,\s*File\ssize\s(bytes):\s*(?[[sep_file_field]]),\s*Device\sID:\s*(?[[sep_file_field]]))?$&lt;/P&gt;

&lt;P&gt;[field_extraction_for_agt_proactive]&lt;BR /&gt;
REGEX = (?i)(?:[[sep_file_prefix]]),\s*(?[[sep_file_field]]),\s*(?:Computer\sname:\s*(?[[sep_file_field]]))?,?\s*(?:IP\sAddress:\s*(?[[sep_file_field]]))?,\s*(?:Detection\stype:\s*(?[[sep_file_field]]))?,\s*(?:First\sseen:\s*(?[[sep_file_field]]))?,\s*(?:Application\sname:\s*(?[[sep_file_field]]))?,\s*(?:Application\stype:\s*(?[[sep_file_field]]))?,\s*(?:Application\sversion:\s*(?[[sep_file_field]]))?,\s*(?:Hash\stype:\s*(?[[sep_file_field]]))?,\s*(?:Application\shash:\s*(?[[sep_file_field]]))?,\s*(?:Company\sname:\s*(?.&lt;EM&gt;))?,\s&lt;/EM&gt;(?:File\ssize\s(bytes):\s*(?[[sep_file_field]]))?,\s*(?:Sensitivity:\s*(?[[sep_file_field]]))?,\s*(?:Detection\sscore:\s*(?[[sep_file_field]]))?,\s*(?:COH\sEngine\sVersion:\s*(?[[sep_file_field]]))?,\s*(?[[sep_file_field]]),\s*(?:Permitted\sapplication\sreason:\s*(?[[sep_file_field]]))?,\s*(?:Disposition:\s*(?[[sep_file_field]]))?,\s*(?:Download\ssite:\s*(?[[sep_file_field]]))?,\s*(?:Web\sdomain:\s*(?.&lt;EM&gt;))?,\s&lt;/EM&gt;(?:Downloaded\sby:\s*(?[[sep_file_field]]))?,\s*(?:Prevalence:\s*(?[[sep_file_field]]))?,\s*(?:Confidence:\s*(?[[sep_file_field]]))?,\s*(?:URL\sTracking\sStatus:\s*(?[[sep_file_field]]))?,\s*(?:Risk\sLevel:\s*(?[[sep_file_field]]))?,?\s*(?:Risk\stype:\s*(?[[sep_file_field]]))?,?\s*(?:Detection\sSource:\s*(?[[sep_file_field]]))?,\s*(?:Source:\s*(?[[sep_file_field]]))?,\s*(?:Risk\sname:\s*(?[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?[[sep_file_field]]))?,\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?:Actual\saction:\s*(?[[sep_file_field]]))?,\s*(?:Requested\saction:\s*(?[[sep_file_field]]))?,\s*(?:Secondary\saction:\s*(?[[sep_file_field]]))?,\s*(?:Event\stime:\s*(?[[sep_file_field]]))?,\s*(?:Inserted:\s*(?[[sep_file_field]]))?,\s*(?:End:\s*(?[[sep_file_field]]))?,\s*(?:Domain:\s*(?[[sep_file_field]]))?,\s*(?:Group:\s*(?[[sep_file_field]]))?,\s*(?:Server:\s*(?[[sep_file_field]]))?,\s*(?[[sep_file_field]]),\s*(?:Source\scomputer:\s*(?[[sep_file_field]]))?,\s*(?:Source\sIP:\s*(?[[sep_file_field]]))?,?\s*(?:Intensive\sProtection\sLevel:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\sissuer:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\ssigner:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\sthumbprint:\s*(?[[sep_file_field]]))?,?\s*(?:Signing\stimestamp:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\sserial\snumber:\s*(?[[sep_file_field]]))?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454500#M55893</guid>
      <dc:creator>jtwind_2</dc:creator>
      <dc:date>2020-09-30T00:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454501#M55894</link>
      <description>&lt;P&gt;what version does this work on? &lt;/P&gt;

&lt;P&gt;I am getting this on 7.0.3;&lt;/P&gt;

&lt;P&gt;Bad regex value: ...  / REGEX; why: unrecognized character after (? or (?-&lt;BR /&gt;
for all those stanzas&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 09:28:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454501#M55894</guid>
      <dc:creator>GDustin</dc:creator>
      <dc:date>2019-05-17T09:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454502#M55895</link>
      <description>&lt;P&gt;@jtwind_2 &lt;BR /&gt;
Can you repost with the Code sample option?&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7041iD425EB5BDD4FB6C8/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;This is from the old 2.3.0 transforms[as an example];&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(?i)(?:[[sep_file_prefix]]),\s*(?&amp;lt;Risk_Action&amp;gt;[[sep_file_field]]),\s*(?:IP\sAddress:\s*(?&amp;lt;IP_Address&amp;gt;[[sep_file_field]]))?,\s*(?:Computer\sname:\s*(?&amp;lt;Computer_Name&amp;gt;[[sep_file_field]]))?,?\s*(?:Intensive\sProtection\sLevel:\s*(?&amp;lt;Intensive_Protection_Level&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sissuer:\s*(?&amp;lt;Certificate_Issuer&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\ssigner:\s*(?&amp;lt;Certificate_Signer&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sthumbprint:\s*(?&amp;lt;Certificate_Thumbprint&amp;gt;[[sep_file_field]]))?,?\s*(?:Signing\stimestamp:\s*(?&amp;lt;Signing_Timestamp&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sserial\snumber:\s*(?&amp;lt;Certificate_Serial_Number&amp;gt;[[sep_file_field]]))?,\s*(?:Source:\s*(?&amp;lt;Source&amp;gt;[[sep_file_field]]))?,\s*(?:Risk\sname:\s*(?&amp;lt;Risk_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?&amp;lt;Occurrences&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;file_path&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Description&amp;gt;[[sep_file_field]]),\s*(?:Actual\saction:\s*(?&amp;lt;vendor_action&amp;gt;[[sep_file_field]]))?,\s*(?:Requested\saction:\s*(?&amp;lt;Requested_Action&amp;gt;[[sep_file_field]]))?,\s*(?:Secondary\saction:\s*(?&amp;lt;Secondary_Action&amp;gt;[[sep_file_field]]))?,\s*(?:Event\stime:\s*(?&amp;lt;Event_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Inserted:\s*(?&amp;lt;Event_Insert_Time&amp;gt;[[sep_file_field]]))?,\s*(?:End:\s*(?&amp;lt;End_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Last\supdate\stime:\s*(?&amp;lt;Last_Update_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Domain:\s*(?&amp;lt;Domain_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Group:\s*(?&amp;lt;Group_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Server:\s*(?&amp;lt;Server_Name&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;user&amp;gt;[[sep_file_field]]),\s*(?:Source\scomputer:\s*(?&amp;lt;Source_Computer_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Source\sIP:\s*(?&amp;lt;Source_Computer_IP&amp;gt;[[sep_file_field]]))?,\s*(?:Disposition:\s*(?&amp;lt;Disposition&amp;gt;[[sep_file_field]]))?,\s*(?:Download\ssite:\s*(?&amp;lt;Download_Site&amp;gt;[[sep_file_field]]))?,\s*(?:Web\sdomain:\s*(?&amp;lt;Web_Domain&amp;gt;.*))?,\s*(?:Downloaded\sby:\s*(?&amp;lt;Downloaded_By&amp;gt;[[sep_file_field]]))?,\s*(?:Prevalence:\s*(?&amp;lt;Prevalence&amp;gt;[[sep_file_field]]))?,\s*(?:Confidence:\s*(?&amp;lt;Confidence&amp;gt;[[sep_file_field]]))?,\s*(?:URL\sTracking\sStatus:\s*(?&amp;lt;URL_Tracking_Status&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;Unknown_Field&amp;gt;[[sep_file_field]]),\s*(?:First\sseen:\s*(?&amp;lt;First_Seen&amp;gt;[[sep_file_field]]))?,\s*(?:Sensitivity:\s*(?&amp;lt;Sensitivity&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;Reason_For_White_Listing&amp;gt;[[sep_file_field]]),\s*(?:Application\shash:\s*(?&amp;lt;Application_Hash&amp;gt;[[sep_file_field]]))?,\s*(?:Hash\stype:\s*(?&amp;lt;Hash_Type&amp;gt;[[sep_file_field]]))?,\s*(?:Company\sname:\s*(?&amp;lt;Company_Name&amp;gt;.*))?,\s*(?:Application\sname:\s(?&amp;lt;Application_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Application\sversion:\s*(?P&amp;lt;Application_Version&amp;gt;.*))?,\s*(?:Application\stype:\s*(?&amp;lt;Application_Type&amp;gt;[[sep_file_field]]))?,\s*(?:File\ssize\s\(bytes\):\s*(?&amp;lt;File_Size&amp;gt;[[sep_file_field]]))?(?:,\s*Category\sset:\s*(?&amp;lt;Category_Set&amp;gt;[[sep_file_field]]),\s*Category\stype:\s*(?&amp;lt;Category_Type&amp;gt;[[sep_file_field]]))?,?\s*(?:Location:\s*(?&amp;lt;Location&amp;gt;[[sep_file_field]]))?
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 17 May 2019 10:57:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454502#M55895</guid>
      <dc:creator>GDustin</dc:creator>
      <dc:date>2019-05-17T10:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454503#M55896</link>
      <description>&lt;P&gt;I am also getting the Bad Regex error, but I'm confused by the latest post.  I tried adding the  (or whatever the verbiage was between the &amp;lt;&amp;gt; in the original transforms Regex per the applicable stanza) in the local file regex where it had been in the original transforms Regex, but am still getting the error. I'm unsure if this was the recommendation, or what additional regex tweaking needs to be performed.  Anyone know if Splunk will be putting out an updated TA for these critical parsing changes?&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 17:45:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454503#M55896</guid>
      <dc:creator>rriegert</dc:creator>
      <dc:date>2019-05-20T17:45:44Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454504#M55897</link>
      <description>&lt;P&gt;Try this:... you'll also want to be running v 2.3.0 (latest as of this writing) of the Symantec add-on... &lt;A href="https://splunkbase.splunk.com/app/2772/"&gt;https://splunkbase.splunk.com/app/2772/&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[field_extraction_for_traffic]
REGEX = (?i)(?:[[sep_file_prefix]]),\s*(?&amp;lt;vendor_severity&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Host_Name&amp;gt;[[sep_file_field]]),\s*(?:Local Host:\s*(?&amp;lt;Local_Host_IP&amp;gt;[[sep_file_field]]))?,\s*(?:Local Port:\s*(?&amp;lt;Local_Port&amp;gt;[[sep_file_field]]))?,\s*(?:Local Host MAC:\s*(?&amp;lt;Local_Host_MAC&amp;gt;[[sep_file_field]]))?,\s*(?:Remote Host IP:\s*(?&amp;lt;Remote_Host_IP&amp;gt;[[sep_file_field]]))?,\s*(?:Remote Host Name:\s*(?&amp;lt;Remote_Host_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Remote Port:\s*(?&amp;lt;Remote_Port&amp;gt;[[sep_file_field]]))?,\s*(?:Remote Host MAC:\s*(?&amp;lt;Remote_Host_MAC&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;Network_Protocol&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Traffic_Direction&amp;gt;[[sep_file_field]]),\s*(?:Begin:\s*(?&amp;lt;Begin_Time&amp;gt;[[sep_file_field]]))?,\s*(?:End:\s*(?&amp;lt;End_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?&amp;lt;Occurrences&amp;gt;[[sep_file_field]]))?,\s*(?:Application:\s*(?&amp;lt;Application_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Rule:\s*(?&amp;lt;rule&amp;gt;[[sep_file_field]]))?,\s*(?:Location:\s*(?&amp;lt;Location&amp;gt;[[sep_file_field]]))?,\s*(?:User:\s*(?&amp;lt;user&amp;gt;[[sep_file_field]]))?,\s*(?:Domain:\s*(?&amp;lt;Domain_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Action:\s*(?&amp;lt;vendor_action&amp;gt;[[sep_file_field]]))?,\s*(?:SHA-256:\s*(?&amp;lt;SHA_256&amp;gt;[[sep_file_field]]))?,\s*(?:MD-5:\s*(?&amp;lt;MD_5&amp;gt;[[sep_file_field]]))?

[field_extraction_for_agt_security]
REGEX = (?i)(?:[[sep_file_prefix]]),\s*(?&amp;lt;vendor_severity&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Host_Name&amp;gt;[[sep_file_field]]),\s*(?:Event Description:\s*(?&amp;lt;Event_Description&amp;gt;[[sep_file_field]])),\s*(?:Local:\s*(?&amp;lt;Local_Host_IP&amp;gt;[[sep_file_field]]))?,\s*(?:Local Host MAC:\s*(?&amp;lt;Local_Host_MAC&amp;gt;[[sep_file_field]]))?,\s*(?:Remote Host Name:\s*(?&amp;lt;Remote_Host_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Remote Host IP:\s*(?&amp;lt;Remote_Host_IP&amp;gt;[[sep_file_field]]))?,\s*(?:Remote Host MAC:\s*(?&amp;lt;Remote_Host_MAC&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;Traffic_Direction&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Network_Protocol&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Hack_Type&amp;gt;[[sep_file_field]]),\s*(?:Begin:\s*(?&amp;lt;Begin_Time&amp;gt;[[sep_file_field]]))?,\s*(?:End:\s*(?&amp;lt;End_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?&amp;lt;Occurrences&amp;gt;[[sep_file_field]]))?,\s*(?:Application:\s*(?&amp;lt;Application_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Location:\s*(?&amp;lt;Location&amp;gt;[[sep_file_field]]))?,\s*(?:User:\s*(?&amp;lt;user&amp;gt;[[sep_file_field]])),\s*(?:Domain:\s*(?&amp;lt;Domain_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Local\sPort\s*(?&amp;lt;Local_Port&amp;gt;[[sep_file_field]]))?,\s*(?:Remote\sPort\s*(?&amp;lt;Remote_Port&amp;gt;[[sep_file_field]]))?,\s*(?:CIDS\sSignature\sID:\s*(?&amp;lt;CIDS_Signature_ID&amp;gt;[[sep_file_field]]))?,\s*(?:CIDS\sSignature\sstring:\s*(?&amp;lt;CIDS_Signature_String&amp;gt;[[sep_file_field]]))?,\s*(?:CIDS\sSignature\sSubID:\s*(?&amp;lt;CIDS_Signature_SubID&amp;gt;[[sep_file_field]]))?,\s*(?:Intrusion\sURL:\s*(?&amp;lt;Intrusion_URL&amp;gt;[[sep_file_field]]))?,\s*(?:Intrusion\sPayload\sURL:\s*(?&amp;lt;Intrusion_Payload_URL&amp;gt;[[sep_file_field]]))?,?\s*(?:SHA-256:\s*(?&amp;lt;SHA_256&amp;gt;[[sep_file_field]]))?,?\s*(?:MD-5:\s*(?&amp;lt;MD_5&amp;gt;[[sep_file_field]]))?

[field_extraction_for_agt_risk]
REGEX = (?i)(?:[[sep_file_prefix]]),\s*(?&amp;lt;Risk_Action&amp;gt;[[sep_file_field]]),\s*(?:IP\sAddress:\s*(?&amp;lt;IP_Address&amp;gt;[[sep_file_field]]))?,\s*(?:Computer\sname:\s*(?&amp;lt;Computer_Name&amp;gt;[^,']*'[^']*'|[^,"]*"[^"]*|[^,]*))?,\s*(?:Source:\s*(?&amp;lt;Source&amp;gt;[[sep_file_field]]))?,\s*(?:Risk\sname:\s*(?&amp;lt;Risk_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?&amp;lt;Occurrences&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;file_path&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Description&amp;gt;[[sep_file_field]]),\s*(?:Actual\saction:\s*(?&amp;lt;vendor_action&amp;gt;[[sep_file_field]]))?,\s*(?:Requested\saction:\s*(?&amp;lt;Requested_Action&amp;gt;[[sep_file_field]]))?,\s*(?:Secondary\saction:\s*(?&amp;lt;Secondary_Action&amp;gt;[[sep_file_field]]))?,\s*(?:Event\stime:\s*(?&amp;lt;Event_Time&amp;gt;[[sep_file_field]]))?,s*(?:Inserted:\s*(?&amp;lt;Event_Insert_Time&amp;gt;[[sep_file_field]]))?,\s*(?:End:\s*(?&amp;lt;End_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Last\supdate\stime:\s*(?&amp;lt;Last_Update_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Domain:\s*(?&amp;lt;Domain_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Group:\s*(?&amp;lt;Group_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Server:\s*(?&amp;lt;Server_Name&amp;gt;[[sep_file_field]]))?,\s*(?:User:\s*(?&amp;lt;user&amp;gt;[[sep_file_field]])),\s*(?:Source\scomputer:\s*(?&amp;lt;Source_Computer_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Source\sIP:\s*(?&amp;lt;Source_Computer_IP&amp;gt;[[sep_file_field]]))?,\s*(?:Disposition:\s*(?&amp;lt;Disposition&amp;gt;[[sep_file_field]]))?,\s*(?:Download\ssite:\s*(?&amp;lt;Download_Site&amp;gt;[[sep_file_field]]))?,\s*(?:Web\sdomain:\s*(?&amp;lt;Web_Domain&amp;gt;.*))?,\s*(?:Downloaded\sby:\s*(?&amp;lt;Downloaded_By&amp;gt;[[sep_file_field]]))?,\s*(?:Prevalence:\s*(?&amp;lt;Prevalence&amp;gt;[[sep_file_field]]))?,\s*(?:Confidence:\s*(?&amp;lt;Confidence&amp;gt;[[sep_file_field]]))?,\s*(?:URL\sTracking\sStatus:\s*(?&amp;lt;URL_Tracking_Status&amp;gt;[[sep_file_field]]))?,\s*(?:First\sseen:\s*(?&amp;lt;First_Seen&amp;gt;[[sep_file_field]]))?,\s*(?:Sensitivity:\s*(?&amp;lt;Sensitivity&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;Reason_For_White_Listing&amp;gt;[[sep_file_field]]),\s*(?:Application\shash:\s*(?&amp;lt;Application_Hash&amp;gt;[[sep_file_field]]))?,\s*(?:Hash\stype:\s*(?&amp;lt;Hash_Type&amp;gt;[[sep_file_field]]))?,\s*(?:Company\sname:\s*(?&amp;lt;Company_Name&amp;gt;.*))?,\s*(?:Application\sname:\s(?&amp;lt;Application_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Application\sversion:\s*(?P&amp;lt;Application_Version&amp;gt;.*))?,\s*(?:Application\stype:\s*(?&amp;lt;Application_Type&amp;gt;[[sep_file_field]]))?,\s*(?:File\ssize\s\(bytes\):\s*(?&amp;lt;File_Size&amp;gt;[[sep_file_field]]))?(?:,\s*Category\sset:\s*(?&amp;lt;Category_Set&amp;gt;[[sep_file_field]]),\s*Category\stype:\s*(?&amp;lt;Category_Type&amp;gt;[[sep_file_field]]))?,?\s*(?:Location:\s*(?&amp;lt;Location&amp;gt;[[sep_file_field]]))?,?\s*(?:Intensive\sProtection\sLevel:\s*(?&amp;lt;Intensive_Protection_Level&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sissuer:\s*(?&amp;lt;Certificate_Issuer&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\ssigner:\s*(?&amp;lt;Certificate_Signer&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sthumbprint:\s*(?&amp;lt;Certificate_Thumbprint&amp;gt;[[sep_file_field]]))?,?\s*(?:Signing\stimestamp:\s*(?&amp;lt;Signing_Timestamp&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sserial\snumber:\s*(?&amp;lt;Certificate_Serial_Number&amp;gt;[[sep_file_field]]))?

[field_extraction_for_agt_behavior]
REGEX = ^(?i)(?:[[sep_file_prefix]]),\s*(?&amp;lt;vendor_severity&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Host_Name&amp;gt;[[sep_file_field]]),?\s*(?&amp;lt;IP_Address&amp;gt;[[sep_file_field]])?,\s*(?&amp;lt;vendor_action&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Description&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;API&amp;gt;[[sep_file_field]]),\s*(?:Begin:\s*(?&amp;lt;Begin_Time&amp;gt;[[sep_file_field]]))?,\s*(?:End:\s*(?&amp;lt;End_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Rule:\s*(?&amp;lt;rule&amp;gt;[[sep_file_field]])),\s*(?&amp;lt;Caller_Process_ID&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Caller_Process_Name&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Return_Address&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Return_Module&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Parameter&amp;gt;[[sep_file_field]]),\s*(?:User:\s*(?&amp;lt;user&amp;gt;[[sep_file_field]])),\s*(?:Domain:\s*(?&amp;lt;Domain_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Action\sType:\s*(?&amp;lt;Action_Type&amp;gt;[[sep_file_field]]))?(?:,\s*File\ssize\s\(bytes\):\s*(?&amp;lt;File_Size&amp;gt;[[sep_file_field]]),\s*Device\sID:\s*(?&amp;lt;Device_ID&amp;gt;[[sep_file_field]]))?$

[field_extraction_for_agt_proactive]
REGEX = (?i)(?:[[sep_file_prefix]]),\s*(?&amp;lt;Risk_Action&amp;gt;[[sep_file_field]]),\s*(?:Computer\sname:\s*(?&amp;lt;Computer_Name&amp;gt;[[sep_file_field]]))?,?\s*(?:IP\sAddress:\s*(?&amp;lt;IP_Address&amp;gt;[[sep_file_field]]))?,\s*(?:Detection\stype:\s*(?&amp;lt;Detection_Type&amp;gt;[[sep_file_field]]))?,\s*(?:First\sseen:\s*(?&amp;lt;First_Seen&amp;gt;[[sep_file_field]]))?,\s*(?:Application\sname:\s*(?&amp;lt;Application_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Application\stype:\s*(?&amp;lt;Application_Type&amp;gt;[[sep_file_field]]))?,\s*(?:Application\sversion:\s*(?&amp;lt;Application_Version&amp;gt;[[sep_file_field]]))?,\s*(?:Hash\stype:\s*(?&amp;lt;Hash_Type&amp;gt;[[sep_file_field]]))?,\s*(?:Application\shash:\s*(?&amp;lt;Application_Hash&amp;gt;[[sep_file_field]]))?,\s*(?:Company\sname:\s*(?&amp;lt;Company_Name&amp;gt;.*))?,\s*(?:File\ssize\s\(bytes\):\s*(?&amp;lt;File_Size&amp;gt;[[sep_file_field]]))?,\s*(?:Sensitivity:\s*(?&amp;lt;Sensitivity&amp;gt;[[sep_file_field]]))?,\s*(?:Detection\sscore:\s*(?&amp;lt;Detection_Score&amp;gt;[[sep_file_field]]))?,\s*(?:COH\sEngine\sVersion:\s*(?&amp;lt;COH_Engine_Version&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;Submission_Recommendation&amp;gt;[[sep_file_field]]),\s*(?:Permitted\sapplication\sreason:\s*(?&amp;lt;Permitted_Application_Reason&amp;gt;[[sep_file_field]]))?,\s*(?:Disposition:\s*(?&amp;lt;Disposition&amp;gt;[[sep_file_field]]))?,\s*(?:Download\ssite:\s*(?&amp;lt;Download_Site&amp;gt;[[sep_file_field]]))?,\s*(?:Web\sdomain:\s*(?&amp;lt;Web_Domain&amp;gt;.*))?,\s*(?:Downloaded\sby:\s*(?&amp;lt;Downloaded_By&amp;gt;[[sep_file_field]]))?,\s*(?:Prevalence:\s*(?&amp;lt;Prevalence&amp;gt;[[sep_file_field]]))?,\s*(?:Confidence:\s*(?&amp;lt;Confidence&amp;gt;[[sep_file_field]]))?,\s*(?:URL\sTracking\sStatus:\s*(?&amp;lt;URL_Tracking_Status&amp;gt;[[sep_file_field]]))?,\s*(?:Risk\sLevel:\s*(?&amp;lt;Risk_Level&amp;gt;[[sep_file_field]]))?,?\s*(?:Risk\stype:\s*(?&amp;lt;Risk_Type&amp;gt;[[sep_file_field]]))?,?\s*(?:Detection\sSource:\s*(?&amp;lt;Detection_Source&amp;gt;[[sep_file_field]]))?,\s*(?:Source:\s*(?&amp;lt;Source&amp;gt;[[sep_file_field]]))?,\s*(?:Risk\sname:\s*(?&amp;lt;Risk_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?&amp;lt;Occurrences&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;file_path&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Description&amp;gt;[[sep_file_field]]),\s*(?:Actual\saction:\s*(?&amp;lt;vendor_action&amp;gt;[[sep_file_field]]))?,\s*(?:Requested\saction:\s*(?&amp;lt;Requested_Action&amp;gt;[[sep_file_field]]))?,\s*(?:Secondary\saction:\s*(?&amp;lt;Secondary_Action&amp;gt;[[sep_file_field]]))?,\s*(?:Event\stime:\s*(?&amp;lt;Event_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Inserted:\s*(?&amp;lt;Event_Insert_Time&amp;gt;[[sep_file_field]]))?,\s*(?:End:\s*(?&amp;lt;End_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Domain:\s*(?&amp;lt;Domain_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Group:\s*(?&amp;lt;Group_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Server:\s*(?&amp;lt;Server_Name&amp;gt;[[sep_file_field]]))?,\s*(?&amp;lt;user&amp;gt;[[sep_file_field]]),\s*(?:Source\scomputer:\s*(?&amp;lt;Source_Computer_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Source\sIP:\s*(?&amp;lt;Source_Computer_IP&amp;gt;[[sep_file_field]]))?,?\s*(?:Intensive\sProtection\sLevel:\s*(?&amp;lt;Intensive_Protection_Level&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sissuer:\s*(?&amp;lt;Certificate_Issuer&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\ssigner:\s*(?&amp;lt;Certificate_Signer&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sthumbprint:\s*(?&amp;lt;Certificate_Thumbprint&amp;gt;[[sep_file_field]]))?,?\s*(?:Signing\stimestamp:\s*(?&amp;lt;Signing_Timestamp&amp;gt;[[sep_file_field]]))?,?\s*(?:Certificate\sserial\snumber:\s*(?&amp;lt;Certificate_Serial_Number&amp;gt;[[sep_file_field]]))?
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 20 May 2019 17:51:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454504#M55897</guid>
      <dc:creator>jtwind_2</dc:creator>
      <dc:date>2019-05-20T17:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454505#M55898</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/76118"&gt;@rriegert&lt;/a&gt; see below, jt come through;&lt;/P&gt;

&lt;P&gt;attempt to reduce confusion:&lt;BR /&gt;
Paste old code in something like regex101&lt;/P&gt;

&lt;P&gt;Take the smallest one as an example:&lt;BR /&gt;
[field_extraction_for_agt_behavior]&lt;/P&gt;

&lt;P&gt;^(?i)(?:[[sep_file_prefix]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),?\s*(?[[sep_file_field]])?,\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?:Begin:\s*(?[[sep_file_field]]))?,\s*(?:End:\s*(?[[sep_file_field]]))?,\s*(?:Rule:\s*(?[[sep_file_field]])),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?:User:\s*(?[[sep_file_field]])),\s*(?:Domain:\s*(?[[sep_file_field]]))?,\s*(?:Action\sType:\s*(?[[sep_file_field]]))?(?:,\s*File\ssize\s(bytes):\s*(?[[sep_file_field]]),\s*Device\sID:\s*(?[[sep_file_field]]))?$&lt;/P&gt;

&lt;P&gt;Get these errors:&lt;BR /&gt;
All the errors detected are listed below, from left to right, as they appear in the pattern.&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
? The preceding token is not quantifiable&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;BR /&gt;
(? Incomplete group structure&lt;BR /&gt;
) Incomplete group structure&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;The problem is when you paste a code such as:&lt;BR /&gt;
    ?&lt;VENDOR_SEVERITY&gt;&lt;BR /&gt;
Without the code option in the answers post, the:&lt;BR /&gt;
    &lt;THISORTHAT&gt;&lt;BR /&gt;
get's filtered or removed;&lt;/THISORTHAT&gt;&lt;/VENDOR_SEVERITY&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Now; Take the smallest one as an example below; and go paste that one in regex101 or similar:&lt;BR /&gt;
[field_extraction_for_agt_behavior]&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;^(?i)(?:[[sep_file_prefix]]),\s*(?&amp;lt;vendor_severity&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Host_Name&amp;gt;[[sep_file_field]]),?\s*(?&amp;lt;IP_Address&amp;gt;[[sep_file_field]])?,\s*(?&amp;lt;vendor_action&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Description&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;API&amp;gt;[[sep_file_field]]),\s*(?:Begin:\s*(?&amp;lt;Begin_Time&amp;gt;[[sep_file_field]]))?,\s*(?:End:\s*(?&amp;lt;End_Time&amp;gt;[[sep_file_field]]))?,\s*(?:Rule:\s*(?&amp;lt;rule&amp;gt;[[sep_file_field]])),\s*(?&amp;lt;Caller_Process_ID&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Caller_Process_Name&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Return_Address&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Return_Module&amp;gt;[[sep_file_field]]),\s*(?&amp;lt;Parameter&amp;gt;[[sep_file_field]]),\s*(?:User:\s*(?&amp;lt;user&amp;gt;[[sep_file_field]])),\s*(?:Domain:\s*(?&amp;lt;Domain_Name&amp;gt;[[sep_file_field]]))?,\s*(?:Action\sType:\s*(?&amp;lt;Action_Type&amp;gt;[[sep_file_field]]))?(?:,\s*File\ssize\s\(bytes\):\s*(?&amp;lt;File_Size&amp;gt;[[sep_file_field]]),\s*Device\sID:\s*(?&amp;lt;Device_ID&amp;gt;[[sep_file_field]]))?$
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;...no errors&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454505#M55898</guid>
      <dc:creator>GDustin</dc:creator>
      <dc:date>2020-09-30T00:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454506#M55899</link>
      <description>&lt;P&gt;So far worked in dev with a one-shot; looking good for prod;Thank you for sharing.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 07:25:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454506#M55899</guid>
      <dc:creator>GDustin</dc:creator>
      <dc:date>2019-05-21T07:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454507#M55900</link>
      <description>&lt;P&gt;some of my code above is still bad/not displaying correctly; it is not presenting the characters "&amp;lt;" or "&amp;gt;", sorry for the confusion&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 23:14:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454507#M55900</guid>
      <dc:creator>GDustin</dc:creator>
      <dc:date>2019-05-22T23:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454508#M55901</link>
      <description>&lt;P&gt;i am using the following for my agt_risk extraction:&lt;/P&gt;

&lt;P&gt;[field_extraction_for_agt_risk]&lt;/P&gt;

&lt;P&gt;REGEX =(?i)(?:[[sep_file_prefix]]),\s*(?[[sep_file_field]]),\s*(?:IP\sAddress:\s*(?[[sep_file_field]]))?,\s*(?:Computer\sname:\s*(?[[sep_file_field]]))?,\s*(?:Source:\s*(?[[sep_file_field]]))?,\s*(?:Risk\sname:\s*(?[[sep_file_field]]))?,\s*(?:Occurrences:\s*(?[[sep_file_field]]))?,\s*(?[[sep_file_field]]),\s*(?[[sep_file_field]]),\s*(?:Actual\saction:\s*(?[[sep_file_field]]))?,\s*(?:Requested\saction:\s*(?[[sep_file_field]]))?,\s*(?:Secondary\saction:\s*(?[[sep_file_field]]))?,\s*(?:Event\stime:\s*(?[[sep_file_field]]))?,\s*(?:Inserted:\s*(?[[sep_file_field]]))?,\s*(?:End:\s*(?[[sep_file_field]]))?,\s*(?:Last\supdate\stime:\s*(?[[sep_file_field]]))?,\s*(?:Domain:\s*(?[[sep_file_field]]))?,\s*(?:Group:\s*(?[[sep_file_field]]))?,\s*(?:Server:\s*(?[[sep_file_field]]))?,\s*(?[[sep_file_field]]),\s*(?:Source\scomputer:\s*(?[[sep_file_field]]))?,\s*(?:Source\sIP:\s*(?[[sep_file_field]]))?,\s*(?:Disposition:\s*(?[[sep_file_field]]))?,\s*(?:Download\ssite:\s*(?[[sep_file_field]]))?,\s*(?:Web\sdomain:\s*(?[[sep_file_field]]))?,\s*(?:Downloaded\sby:\s*(?[[sep_file_field]]))?,\s*(?:Prevalence:\s*(?[[sep_file_field]]))?,\s*(?:Confidence:\s*(?[[sep_file_field]]))?,\s*(?:URL\sTracking\sStatus:\s*(?[[sep_file_field]]))?,\s*(?:First\sseen:\s*(?[[sep_file_field]]))?,\s*(?:Sensitivity:\s*(?[[sep_file_field]]))?,\s*(?[[sep_file_field]]),\s*(?:Application\shash:\s*(?[[sep_file_field]]))?,\s*(?:Hash\stype:\s*(?[[sep_file_field]]))?,\s*(?:Company\sname:\s*(?.&lt;EM&gt;))?,\s&lt;/EM&gt;(?:Application\sname:\s(?[[sep_file_field]]))?,\s*(?:Application\sversion:\s*(?P[[sep_file_field]]))?,\s*(?:Application\stype:\s*(?[[sep_file_field]]))?,\s*(?:File\ssize\s(bytes):\s*(?[[sep_file_field]]))?,\s*(?:Category\sset:\s*(?[[sep_file_field]]))?,\s*(?:Category\stype:\s*(?[[sep_file_field]]))?,?\s*(?:Location:\s*(?[[sep_file_field]]))?,\s*(?:Intensive\sProtection\sLevel:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\sissuer:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\ssigner:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\sthumbprint:\s*(?[[sep_file_field]]))?,?\s*(?:Signing\stimestamp:\s*(?[[sep_file_field]]))?,?\s*(?:Certificate\sserial\snumber:\s*(?[[sep_file_field]]))?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:54:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454508#M55901</guid>
      <dc:creator>archme</dc:creator>
      <dc:date>2020-09-30T00:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454509#M55902</link>
      <description>&lt;P&gt;This worked for me as well. In Splunk Cloud - updated the configuration via the webui and refreshed the searches. Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 17:36:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454509#M55902</guid>
      <dc:creator>testrake_trek</dc:creator>
      <dc:date>2019-07-31T17:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454510#M55903</link>
      <description>&lt;P&gt;We took a different approach as the transforms option gave us problems when not all the fields existed all this time in the events we were getting. As such we updated the local/props.conf with the the below and haven't had any problem reported yet:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[symantec:ep:security:file]
EXTRACT-security_file_fields = \[name\]:(?P&amp;lt;name&amp;gt;.+?)\[class\]:(?P&amp;lt;class&amp;gt;.+?)\[guid\]:(?P&amp;lt;guid&amp;gt;.+?)\[deviceID\]:(?P&amp;lt;deviceID&amp;gt;.+)[\\\\](?P&amp;lt;deviceSN&amp;gt;.+?)\,

[symantec:ep:agents:db]
FIELDALIAS-user = CURRENT_LOGIN_USER AS user
FIELDALIAS-dest = COMPUTER_NAME AS dest
FIELDALIAS-ip = ip_address AS dest_ip
FIELDALIAS-dest_mac = mac_address AS dest_mac
FIELDALIAS-domain = domain_name AS dest_nt_domain
FIELDALIAS-product_ver = AGENT_VERSION AS product_version
FIELDALIAS-signature_ver = AV_REVISION AS signature_version
EVAL-vendor = "Symantec"
EVAL-product = "Endpoint Protection"
EVAL-vendor_product = "Symantec Endpoint Protection"

[symantec:ep:proactive:file]
EXTRACT-proactive_downloaded_by = Downloaded\sby\:\s(?&amp;lt;Downloaded_By&amp;gt;.*?[^\,]*)
EXTRACT-proactive_prevalance = Prevalence\:\s(?&amp;lt;Prevalence&amp;gt;.*?[^\,]*)
EXTRACT-proactive_url_track = URL\sTracking\sStatus\:\s(?&amp;lt;URL_Tracking_Status&amp;gt;.*?[^\,]*)
EXTRACT-proactive_first_seen = First\sSeen\:\s(?&amp;lt;First_Seen&amp;gt;.*?[^\,]*)
EXTRACT-proactive_sensitivity = Sensitivity\:\s(?&amp;lt;Sensitivity&amp;gt;.*?[^\,]*)
EXTRACT-proactive_app_hash = Application\shash\:\s(?&amp;lt;Application_Hash&amp;gt;.*?[^\,]*)
EXTRACT-proactive_hash_type = Hash\stype\:\s(?&amp;lt;Hash_Type&amp;gt;.*?[^\,]*)
EXTRACT-proactive_app_name = Application\sname\:\s(?&amp;lt;Application_Name&amp;gt;.*?[^\,]*) 
EXTRACT-proactive_app_ver = Application\sversion\:\s(?&amp;lt;Application_Version&amp;gt;.*?[^\,]*)
EXTRACT-proactive_app_type = Application\stype\:\s(?&amp;lt;Application_Type&amp;gt;.*?[^\,]*)
EXTRACT-proactive_file_size = File\ssize\s\(bytes\)\:\s(?&amp;lt;File_Size&amp;gt;.*?[^\,]*)
EXTRACT-proactive_location = Location\:\s(?&amp;lt;Location&amp;gt;.*?[^\,]*)
EXTRACT-proactive_intensive_protection_lvl = Intensive\sProtection\sLevel\:\s(?&amp;lt;Intensive_Protection_Level&amp;gt;.*?[^\,]*)
EXTRACT-proactive_cert_issuer = Certificate\sissuer\:\s(?&amp;lt;Certificate_Issuer&amp;gt;.*?[^\,]*)
EXTRACT-proactive_cert_signer = Certificate\ssigner\:\s(?&amp;lt;Certificate_Signer&amp;gt;.*?[^\,]*)
EXTRACT-proactive_cert_thumbprint = Certificate\sthumbprint\:\s(?&amp;lt;Certificate_Thumbprint&amp;gt;.*?[^\,]*)
EXTRACT-proactive_signing_timestamp = Signing\stimestamp\:\s(?&amp;lt;Signing_Timestamp&amp;gt;.*?[^\,]*)
EXTRACT-proactive_cert_serial_no = Certificate\sserial\snumber\:\s(?&amp;lt;Certificate_Serial_Number&amp;gt;.*?[^\,]*)
EXTRACT-proactive_ip = IP\sAddress\:\s+(?&amp;lt;IP_Address&amp;gt;\d[^\,]+)
EXTRACT-proactive_comp_name = Computer\sname\:\s(?&amp;lt;Computer_Name&amp;gt;\w[^\,]+)
EXTRACT-proactive_src = Source\:\s(?&amp;lt;Source&amp;gt;\w[^\,]+)
EXTRACT-proactive_name = Risk\sname\:\s(?&amp;lt;Risk_Name&amp;gt;\w[^\,]+)
EXTRACT-proactive_occurrences = Occurrences\:\s+(?&amp;lt;Occurrences&amp;gt;\d[^\,]*)\,(?&amp;lt;file_path&amp;gt;\w[^\,]+)\,(?&amp;lt;Description&amp;gt;\w*)
EXTRACT-proactive_actual_action = Actual\saction\:\s(?&amp;lt;vendor_action&amp;gt;\w[^\,]+)
EXTRACT-proactive_requested_action = Requested\saction\:\s(?&amp;lt;Requested_Action&amp;gt;\w[^\,]+)
EXTRACT-proactive_secondary_action = Secondary\saction\:\s(?&amp;lt;Secondary_Action&amp;gt;\w[^\,]+)
EXTRACT-proactive_event_time = Event\stime\:\s(?&amp;lt;Event_Time&amp;gt;\d[^\,]+)
EXTRACT-proactive_insert_time = Inserted\:\s(?&amp;lt;Event_Insert_Time&amp;gt;\d[^\,]+)
EXTRACT-proactive_end_time = End\:\s(?&amp;lt;End_Time&amp;gt;\d[^\,]+)
EXTRACT-proactive_domain_name = Domain\:\s(?&amp;lt;Domain_Name&amp;gt;\w[^\,]+)
EXTRACT-proactive_group_name = Group\:\s(?&amp;lt;Group_Name&amp;gt;\w[^\,]+)
EXTRACT-proactive_server_name = Server\:\s(?&amp;lt;Server_Name&amp;gt;\w[^\,]+)
EXTRACT-proactive_user_name = User\:\s(?&amp;lt;user&amp;gt;\w[^\,]+)
EXTRACT-proactive_src_name = Source\scomputer\:\s(?&amp;lt;Source_Computer_Name&amp;gt;.*?[^\,]*)
EXTRACT-proactive_src_ip = Source\sIP\:\s(?&amp;lt;Source_Computer_IP&amp;gt;.*?[^\,]*)
EXTRACT-proactive_disposition = Disposition\:\s(?&amp;lt;Disposition&amp;gt;\w[^\,]+)
EXTRACT-proactive_download_site = Download\ssite\:\s(?&amp;lt;Download_Site&amp;gt;.*?[^\,]*)
EXTRACT-proactive_web_domain = Web\sdomain\:\s(?&amp;lt;Web_Domain&amp;gt;.*?[^\,]*)
EXTRACT-proactive_confidence = Confidence\:\s(?&amp;lt;Confidence&amp;gt;.*?[^\,]*)
EXTRACT-proactive_action = ^[\d\-\s\:]+\,(?&amp;lt;Risk_Action&amp;gt;.*?[^\,]*)
EXTRACT-proactive_detection_type = Detection\stype\:\s+(?&amp;lt;Detection_Type&amp;gt;.*?[^\,]*)
EXTRACT-proactive_detection_score = Detection\sscore\:\s(?&amp;lt;Detection_Score&amp;gt;.*?[^\,]*)
EXTRACT-proactive_coh_engine_ver = COH\sEngine\sVersion\:\s(?&amp;lt;coh_engine_version&amp;gt;.*?[^\,]*)\,(?&amp;lt;Submission_Recommendation&amp;gt;.*?[^\,]*)
EXTRACT-proactive_permitted_app_reason = Permitted\sapplication\sreason\:\s(?&amp;lt;Permitted_Application_Reason&amp;gt;.*?[^\,]*)
EXTRACT-proactive_risk_lvl = Risk\sLevel\:\s(?&amp;lt;Risk_Level&amp;gt;.*?[^\,]*)
EXTRACT-proactive_risk_type = Risk\stype\:\s(?&amp;lt;Risk_Type&amp;gt;.*?[^\,]*)

[symantec:ep:risk:file]
EXTRACT-risk_downloaded_by = Downloaded\sby\:\s(?&amp;lt;Downloaded_By&amp;gt;.*?[^\,]*)
EXTRACT-risk_prevalance = Prevalence\:\s(?&amp;lt;Prevalence&amp;gt;.*?[^\,]*)
EXTRACT-risk_url_track = URL\sTracking\sStatus\:\s(?&amp;lt;URL_Tracking_Status&amp;gt;.*?[^\,]*)
EXTRACT-risk_first_seen = First\sSeen\:\s(?&amp;lt;First_Seen&amp;gt;.*?[^\,]*)
EXTRACT-risk_sensitivity = Sensitivity\:\s(?&amp;lt;Sensitivity&amp;gt;.*?[^\,]*)\,(?&amp;lt;Reason_For_White_Listing&amp;gt;.*?[^\,]*)
EXTRACT-risk_app_hash = Application\shash\:\s(?&amp;lt;Application_Hash&amp;gt;.*?[^\,]*)
EXTRACT-risk_hash_type = Hash\stype\:\s(?&amp;lt;Hash_Type&amp;gt;.*?[^\,]*)
EXTRACT-risk_co_name = Company\sname\:\s(?&amp;lt;Company_Name&amp;gt;.*?[^\,]*)
EXTRACT-risk_app_name = Application\sname\:\s(?&amp;lt;Application_Name&amp;gt;.*?[^\,]*) 
EXTRACT-risk_app_ver = Application\sversion\:\s(?&amp;lt;Application_Version&amp;gt;.*?[^\,]*)
EXTRACT-risk_app_type = Application\stype\:\s(?&amp;lt;Application_Type&amp;gt;.*?[^\,]*)
EXTRACT-risk_file_size = File\ssize\s\(bytes\)\:\s(?&amp;lt;File_Size&amp;gt;.*?[^\,]*)
EXTRACT-risk_cat_set = Category\sset\:\s(?&amp;lt;Category_Set&amp;gt;.*?[^\,]*)
EXTRACT-risk_cat_type = Category\stype\:\s(?&amp;lt;Category_Type&amp;gt;.*?[^\,]*)
EXTRACT-risk_location = Location\:\s(?&amp;lt;Location&amp;gt;.*?[^\,]*)
EXTRACT-risk_intensive_protection_lvl = Intensive\sProtection\sLevel\:\s(?&amp;lt;Intensive_Protection_Level&amp;gt;.*?[^\,]*)
EXTRACT-risk_cert_issuer = Certificate\sissuer\:\s(?&amp;lt;Certificate_Issuer&amp;gt;.*?[^\,]*)
EXTRACT-risk_cert_signer = Certificate\ssigner\:\s(?&amp;lt;Certificate_Signer&amp;gt;.*?[^\,]*)
EXTRACT-risk_cert_thumbprint = Certificate\sthumbprint\:\s(?&amp;lt;Certificate_Thumbprint&amp;gt;.*?[^\,]*)
EXTRACT-risk_signing_timestamp = Signing\stimestamp\:\s(?&amp;lt;Signing_Timestamp&amp;gt;.*?[^\,]*)
EXTRACT-risk_cert_serial_no = Certificate\sserial\snumber\:\s(?&amp;lt;Certificate_Serial_Number&amp;gt;.*?[^\,]*)
EXTRACT-risk_ip = IP\sAddress\:\s+(?&amp;lt;IP_Address&amp;gt;\d[^\,]+)
EXTRACT-risk_comp_name = Computer\sname\:\s(?&amp;lt;Computer_Name&amp;gt;\w[^\,]+)
EXTRACT-risk_src = Source\:\s(?&amp;lt;Source&amp;gt;\w[^\,]+)
EXTRACT-risk_name = Risk\sname\:\s(?&amp;lt;Risk_Name&amp;gt;\w[^\,]+)
EXTRACT-risk_occurrences = Occurrences\:\s+(?&amp;lt;Occurrences&amp;gt;\d[^\,]*)\,(?&amp;lt;file_path&amp;gt;\w[^\,]+)\,(?&amp;lt;Description&amp;gt;\w*)
EXTRACT-risk_actual_action = Actual\saction\:\s(?&amp;lt;vendor_action&amp;gt;\w[^\,]+)
EXTRACT-risk_requested_action = Requested\saction\:\s(?&amp;lt;Requested_Action&amp;gt;\w[^\,]+)
EXTRACT-risk_secondary_action = Secondary\saction\:\s(?&amp;lt;Secondary_Action&amp;gt;\w[^\,]+)
EXTRACT-risk_event_time = Event\stime\:\s(?&amp;lt;Event_Time&amp;gt;\d[^\,]+)
EXTRACT-risk_insert_time = Inserted\:\s(?&amp;lt;Event_Insert_Time&amp;gt;\d[^\,]+)
EXTRACT-risk_end_time = End\:\s(?&amp;lt;End_Time&amp;gt;\d[^\,]+)
EXTRACT-risk_update_time = Last\supdate\stime\:\s(?&amp;lt;Last_Update_Time&amp;gt;\d[^\,]+)
EXTRACT-risk_domain_name = Domain\:\s(?&amp;lt;Domain_Name&amp;gt;\w[^\,]+)
EXTRACT-risk_group_name = Group\:\s(?&amp;lt;Group_Name&amp;gt;\w[^\,]+)
EXTRACT-risk_server_name = Server\:\s(?&amp;lt;Server_Name&amp;gt;\w[^\,]+)
EXTRACT-risk_user_name = User\:\s(?&amp;lt;user&amp;gt;\w[^\,]+)
EXTRACT-risk_src_name = Source\scomputer\:\s(?&amp;lt;Source_Computer_Name&amp;gt;.*?[^\,]*)
EXTRACT-risk_src_ip = Source\sIP\:\s(?&amp;lt;Source_Computer_IP&amp;gt;.*?[^\,]*)
EXTRACT-risk_disposition = Disposition\:\s(?&amp;lt;Disposition&amp;gt;\w[^\,]+)
EXTRACT-risk_download_site = Download\ssite\:\s(?&amp;lt;Download_Site&amp;gt;.*?[^\,]*)
EXTRACT-risk_web_domain = Web\sdomain\:\s(?&amp;lt;Web_Domain&amp;gt;.*?[^\,]*)
EXTRACT-risk_confidence = Confidence\:\s(?&amp;lt;Confidence&amp;gt;.*?[^\,]*)
EXTRACT-risk_action = ^[\d\-\s\:]+\,(?&amp;lt;Risk_Action&amp;gt;.*?[^\,]*)

[symantec:ep:security:file]
EXTRACT-security_vendor_severity = ^[\d\-\s\:]+\,(?&amp;lt;vendor_severity&amp;gt;.*?[^\,]*)\,(?&amp;lt;Host_Name&amp;gt;\w[^\,]+)
EXTRACT-security_event_desc = Event\sDescription(.*?)(?:\"\,|\s\w+\:|\s+\[\w+\]\:)
EXTRACT-security_domain_name = Domain\:\s(?&amp;lt;Domain_Name&amp;gt;\w[^\,]+)
EXTRACT-security_location = Location\:\s(?&amp;lt;Location&amp;gt;.*?[^\,]*)
EXTRACT-security_begin_time = Begin\:\s(?&amp;lt;Begin_Time&amp;gt;\d[^\,]+)
EXTRACT-security_end_time = End\:\s(?&amp;lt;End_Time&amp;gt;\d[^\,]+)
EXTRACT-security_occurrences = Occurrences\:\s+(?&amp;lt;Occurrences&amp;gt;\d[^\,]*)
EXTRACT-security_user_name = User\:\s(?&amp;lt;user&amp;gt;\w[^\,]+)
EXTRACT-security_local_pt = Local\sPort\:\s+(?&amp;lt;Local_Port&amp;gt;\d[^\,]*)
EXTRACT-security_remote_pt = Remote\sPort\:\s+(?&amp;lt;Remote_Port&amp;gt;\d[^\,]*)
EXTRACT-security_local_ip = Local\:\s+(?&amp;lt;Local_Host_IP&amp;gt;\d[^\,]+)
EXTRACT-security_remote_name = Remote\s\Host\sName\:\s(?&amp;lt;Remote_Host_Name&amp;gt;.*?[^\,]*)
EXTRACT-security_remote_ip = Remote\sHost\sIP\:\s(?&amp;lt;Remote_Host_IP&amp;gt;\d[^\,]+)
EXTRACT-security_local_mac = Local\sHost\sMAC\:\s(?&amp;lt;Local_Host_MAC&amp;gt;\w[^\,]+)
EXTRACT-security_intrusion_url = Intrusion\sURL\:\s(?&amp;lt;Intrusion_URL&amp;gt;.*?[^\,]*)
EXTRACT-security_intrusion_payload_url = Intrusion\sPayload\sURL\:\s(?&amp;lt;Intrusion_Payload_URL&amp;gt;.*?[^\,]*)
EXTRACT-security_md5 = MD\-5\:\s(?&amp;lt;MD_5&amp;gt;.*?[^\,]*)
EXTRACT-security_sha256 = SHA\-256\:\s(?&amp;lt;SHA_256&amp;gt;.*?[^\,]*)
EXTRACT-security_signature_id = CIDS\sSignature\sID\:\s(?&amp;lt;CIDS_Signature_ID&amp;gt;.*?[^\,]*)
EXTRACT-security_signature_string = CIDS\sSignature\sstring\:\s(?&amp;lt;CIDS_Signature_String&amp;gt;.*?[^\,]*)
EXTRACT-security_signature_subid = CIDS\sSignature\sSubID\:\s(?&amp;lt;CIDS_Signature_SubID&amp;gt;.*?[^\,]*)
EXTRACT-security_app_name = Application\:\s(?&amp;lt;Application_Name&amp;gt;.*?[^\,]*)
EXTRACT-security_remote_mac = Remote\sHost\sMAC\:\s(?&amp;lt;Remote_Host_MAC&amp;gt;\d[^\,]+)\,(?&amp;lt;Traffic_Direction&amp;gt;\w[^\,]+)\,(?&amp;lt;Network_Protocol&amp;gt;\d[^\,]*)\,(?&amp;lt;Hack_Type&amp;gt;\w*)
EXTRACT-security_app_path = Application\spath\:\s(?&amp;lt;Application_Path&amp;gt;.*?[^\,]*)
EXTRACT-security_sid = \[SID\:\s(?&amp;lt;SID&amp;gt;\d[^\]]+)
EXTRACT-security_audit = Audit\:\s(?&amp;lt;Audit&amp;gt;.*?[^\,.]*)(?=.\s|\,)
EXTRACT-security_requirement = Requirement\:\s(?&amp;lt;Requirement1&amp;gt;.*?[^\,]*)\sRequirement\:\s(?&amp;lt;Requirement2&amp;gt;.*?[^\,]*)

[symantec:ep:traffic:file]
EXTRACT-traffic_vendor_severity = ^[\d\-\s\:]+\,(?&amp;lt;vendor_severity&amp;gt;.*?[^\,]*)\,(?&amp;lt;Host_Name&amp;gt;\w[^\,]+)
EXTRACT-traffic_domain_name = Domain\:\s(?&amp;lt;Domain_Name&amp;gt;\w[^\,]+)
EXTRACT-traffic_location = Location\:\s(?&amp;lt;Location&amp;gt;.*?[^\,]*)
EXTRACT-traffic_begin_time = Begin\:\s(?&amp;lt;Begin_Time&amp;gt;\d[^\,]+)
EXTRACT-traffic_end_time = End\:\s(?&amp;lt;End_Time&amp;gt;\d[^\,]+)
EXTRACT-traffic_occurrences = Occurrences\:\s+(?&amp;lt;Occurrences&amp;gt;\d[^\,]*)
EXTRACT-traffic_user_name = User\:\s(?&amp;lt;user&amp;gt;\w[^\,]+)
EXTRACT-traffic_local_pt = Local\sPort\:\s+(?&amp;lt;Local_Port&amp;gt;\d[^\,]*)
EXTRACT-traffic_remote_pt = Remote\sPort\:\s+(?&amp;lt;Remote_Port&amp;gt;\d[^\,]*)
EXTRACT-traffic_remote_name = Remote\s\Host\sName\:\s(?&amp;lt;Remote_Host_Name&amp;gt;.*?[^\,]*)
EXTRACT-traffic_remote_ip = Remote\sHost\sIP\:\s(?&amp;lt;Remote_Host_IP&amp;gt;\d[^\,]+)
EXTRACT-traffic_local_mac = Local\sHost\sMAC\:\s(?&amp;lt;Local_Host_MAC&amp;gt;\w[^\,]+)
EXTRACT-traffic_md5 = MD\-5\:\s(?&amp;lt;MD_5&amp;gt;.*?[^\,]*)
EXTRACT-traffic_sha256 = SHA\-256\:\s(?&amp;lt;SHA_256&amp;gt;.*?[^\,]*)
EXTRACT-traffic_app_name = Application\:\s(?&amp;lt;Application_Name&amp;gt;.*?[^\,]*)
EXTRACT-traffic_local_ip = Local\sHost\:\s+(?&amp;lt;Local_Host_IP&amp;gt;\d[^\,]+)
EXTRACT-traffic_remote_mac = Remote\sHost\sMAC\:\s(?&amp;lt;Remote_Host_MAC&amp;gt;\d[^\,]+)\,(?&amp;lt;Network_Protocol&amp;gt;\d[^\,]*)\,(?&amp;lt;Traffic_Direction&amp;gt;\w[^\,]+)
EXTRACT-traffic_vendor_action = Action\:\s(?&amp;lt;vendor_action&amp;gt;\w[^\,]+)
EXTRACT-traffic_rule_name = Rule\:\s(?&amp;lt;Rule_Name&amp;gt;\w[^\,]+)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 31 Jul 2019 18:42:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454510#M55903</guid>
      <dc:creator>csperry_splunk</dc:creator>
      <dc:date>2019-07-31T18:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454511#M55904</link>
      <description>&lt;P&gt;Thanks for putting this together. It worked perfectly.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 13:04:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454511#M55904</guid>
      <dc:creator>rubacker527</dc:creator>
      <dc:date>2019-08-22T13:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454512#M55905</link>
      <description>&lt;P&gt;You mean &lt;CODE&gt;props.conf&lt;/CODE&gt;, correct?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 14:43:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454512#M55905</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2019-08-23T14:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454513#M55906</link>
      <description>&lt;P&gt;That is exactly what I meant.  I just typed the wrong file name in.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 14:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454513#M55906</guid>
      <dc:creator>csperry_splunk</dc:creator>
      <dc:date>2019-08-23T14:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454514#M55907</link>
      <description>&lt;P&gt;Fixed the bad file name---thanks&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 14:51:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454514#M55907</guid>
      <dc:creator>csperry_splunk</dc:creator>
      <dc:date>2019-08-23T14:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454515#M55908</link>
      <description>&lt;P&gt;@csperry my guys just deployed 14.2RU1Mp1 any idea if that one is covered by your props method? Immediately my analysts told me; symantec:ep:security:file /  [field_extraction_for_agt_security] went away; the only change I saw was  "Local:" went to "Local Host IP:" in the raw logs, so I tried to rig some tests with | rex but it does not seem to fix all of it, but i am only just learning. If you have any insight or an update I'll buy you a cola and conf man. I'll see if I can put your props up on the SHC after hours tonight.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:55:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454515#M55908</guid>
      <dc:creator>GDustin</dc:creator>
      <dc:date>2020-09-30T01:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454516#M55909</link>
      <description>&lt;P&gt;14.2RU1Mp1 (14.2.4814.1101).&lt;BR /&gt;
&lt;A href="https://support.symantec.com/us/en/article.TECH154475.html"&gt;https://support.symantec.com/us/en/article.TECH154475.html&lt;/A&gt;&lt;BR /&gt;
Name    Version/Build   Release Date&lt;BR /&gt;
(General Availability)&lt;BR /&gt;
14.2.1.1 (14.2 RU1 MP1) 14.2.4814.1101  August 20, 2019&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 05:27:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454516#M55909</guid>
      <dc:creator>GDustin</dc:creator>
      <dc:date>2019-08-27T05:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454517#M55910</link>
      <description>&lt;P&gt;@csperry; False alarm, yes props method looks good and gets our dashboards populating again; Thanks.&lt;/P&gt;

&lt;P&gt;`&lt;BR /&gt;
symantec:ep:security:file : EXTRACT-security_local_ip&lt;BR /&gt;
Inline  Local\sHost\sIP:\s+(?&lt;LOCAL_HOST_IP&gt;\d[^\,]+)  No owner    Splunk_TA_symantec-ep   Global &lt;/LOCAL_HOST_IP&gt;&lt;/P&gt;

&lt;P&gt;[“Original”] Local:\s+(?\d[^\,]+)&lt;BR /&gt;
[“No Go”] Local Host IP:\s+(?\d[^\,]+)&lt;BR /&gt;
[“Go”] Local\sHost\sIP:\s+(?\d[^\,]+)&lt;BR /&gt;
`&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454517#M55910</guid>
      <dc:creator>GDustin</dc:creator>
      <dc:date>2020-09-30T01:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454518#M55911</link>
      <description>&lt;P&gt;Thanks, this worked for me&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 05:49:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454518#M55911</guid>
      <dc:creator>dsofoulis</dc:creator>
      <dc:date>2019-08-28T05:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: SEP 14.2 RU1 log format change</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454519#M55912</link>
      <description>&lt;P&gt;This is a much better idea.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 06:10:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SEP-14-2-RU1-log-format-change/m-p/454519#M55912</guid>
      <dc:creator>jeremyhagand61</dc:creator>
      <dc:date>2019-09-16T06:10:56Z</dc:date>
    </item>
  </channel>
</rss>

