<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TRANSFORMS-null = setnull in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574738#M10700</link>
    <description>&lt;P&gt;Again, to properly diagnose a regex problem we need to see the events that are to be matched.&amp;nbsp; Not just a tiny snippet, either.&amp;nbsp; Feel free to anonymize sensitive data.&lt;/P&gt;&lt;P&gt;Have you tested your regular expressions on a site like regex101.com?&lt;/P&gt;</description>
    <pubDate>Fri, 12 Nov 2021 13:16:19 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-11-12T13:16:19Z</dc:date>
    <item>
      <title>TRANSFORMS-null = setnull</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574388#M10657</link>
      <description>&lt;OL&gt;&lt;LI&gt;&lt;DIV class=""&gt;In props.conf, set the TRANSFORMS-null attribute:&lt;PRE&gt;[ActiveDirectory]
TRANSFORMS-null= setnull&lt;/PRE&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;Create a corresponding stanza in transforms.conf. Set DEST_KEY to "queue" and FORMAT to "nullQueue":&lt;PRE&gt;[setnull]
REGEX = \[&lt;SPAN class=""&gt;ms_Mcs_&lt;/SPAN&gt;&lt;SPAN class=""&gt;AdmPwdExpirationTime&lt;/SPAN&gt;\]
DEST_KEY = queue
FORMAT = nullQueue&lt;/PRE&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;Restart Splunk Enterprise.&lt;BR /&gt;&lt;BR /&gt;field =&amp;nbsp;&lt;SPAN class=""&gt;ms_Mcs_&lt;/SPAN&gt;&lt;SPAN class=""&gt;AdmPwdExpirationTime&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;the values ​​are still in the index&lt;/SPAN&gt;&lt;BR /&gt;Not working. &amp;nbsp;what did I indicate wrong?&lt;/DIV&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 10 Nov 2021 11:13:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574388#M10657</guid>
      <dc:creator>gitingua</dc:creator>
      <dc:date>2021-11-10T11:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: TRANSFORMS-null = setnull</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574403#M10660</link>
      <description>&lt;P&gt;There likely is an error in the regex, but to know that for sure we'll need to see some example data.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 13:25:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574403#M10660</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-11-10T13:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: TRANSFORMS-null = setnull</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574498#M10672</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example&lt;/P&gt;&lt;P&gt;2Wc23q&lt;/P&gt;&lt;P&gt;C23gAwe3&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 21:21:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574498#M10672</guid>
      <dc:creator>gitingua</dc:creator>
      <dc:date>2021-11-10T21:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: TRANSFORMS-null = setnull</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574573#M10683</link>
      <description>&lt;P&gt;There's the problem.&amp;nbsp; The example data does not match the regex since none of them contain the string "ms_Mcs_AdmPwdExpirationTime".&amp;nbsp; You'll have to find a regular expression that matches all expected strings you wish to send to the null queue.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 13:40:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574573#M10683</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-11-11T13:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: TRANSFORMS-null = setnull</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574576#M10684</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I was wrong. given string. "ms_Mcs_AdmPwd"&amp;nbsp;there are random symbols of the unit and letters&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 13:49:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574576#M10684</guid>
      <dc:creator>gitingua</dc:creator>
      <dc:date>2021-11-11T13:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: TRANSFORMS-null = setnull</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574678#M10695</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;props.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN&gt;Active&lt;/SPAN&gt;&lt;SPAN&gt;Directory]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TRANSFORMS-null = setnull&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;transforms.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[setnull]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;REGEX = ms-Mcs-AdmPwd\s*=(.*)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DEST_KEY = queue&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FORMAT = nullQueue&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;not working&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 01:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574678#M10695</guid>
      <dc:creator>gitingua</dc:creator>
      <dc:date>2021-11-12T01:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: TRANSFORMS-null = setnull</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574738#M10700</link>
      <description>&lt;P&gt;Again, to properly diagnose a regex problem we need to see the events that are to be matched.&amp;nbsp; Not just a tiny snippet, either.&amp;nbsp; Feel free to anonymize sensitive data.&lt;/P&gt;&lt;P&gt;Have you tested your regular expressions on a site like regex101.com?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 13:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574738#M10700</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-11-12T13:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: TRANSFORMS-null = setnull</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574743#M10701</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Снимок экрана 2021-11-12 в 17.21.43.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16838i7E447E31A086802B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Снимок экрана 2021-11-12 в 17.21.43.png" alt="Снимок экрана 2021-11-12 в 17.21.43.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes. check in regex101. enable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;tried different regex methods working. now standing which is in the picture above&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 14:24:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TRANSFORMS-null-setnull/m-p/574743#M10701</guid>
      <dc:creator>gitingua</dc:creator>
      <dc:date>2021-11-12T14:24:10Z</dc:date>
    </item>
  </channel>
</rss>

