<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Import registry (regedit) data into Splunk. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583143#M102753</link>
    <description>&lt;P&gt;Where it should go this&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;^\[&amp;nbsp; &amp;nbsp;as it doesn't do anything ...&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 31 Jan 2022 21:59:32 GMT</pubDate>
    <dc:creator>bogdan_nicolesc</dc:creator>
    <dc:date>2022-01-31T21:59:32Z</dc:date>
    <item>
      <title>Import registry (regedit) data into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583033#M102730</link>
      <description>&lt;P&gt;What i would like to do is to take this form from regedit,&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bogdan_nicolesc_0-1643568174381.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17753i6341CA23385BC2AE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bogdan_nicolesc_0-1643568174381.png" alt="bogdan_nicolesc_0-1643568174381.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and splash it into Splunk.&lt;/P&gt;&lt;P&gt;I have exported data from \WMI\Autologger level, put a sort of serial number at each "line" and tried to convert it into .csv&lt;/P&gt;&lt;P&gt;When i Add Data and do a index once file, i get this&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bogdan_nicolesc_1-1643569406712.png" style="width: 772px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17754i0D7F51CE7A2DB432/image-dimensions/772x108?v=v2" width="772" height="108" role="button" title="bogdan_nicolesc_1-1643569406712.png" alt="bogdan_nicolesc_1-1643569406712.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My main request is to be able to do a table with all that information spreaded on multiple columns. Would help me alot.&lt;BR /&gt;What can i do or moddify in my file so splunk could know what is what and what is going where.&lt;BR /&gt;&lt;BR /&gt;Should i leave it like this, or woud be better to be multiple info in the same "row"?&lt;/P&gt;&lt;P&gt;Instead of this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bogdan_nicolesc_2-1643570831181.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17755iF031E50FDDB5A508/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bogdan_nicolesc_2-1643570831181.png" alt="bogdan_nicolesc_2-1643570831181.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'm thinking more about at this example:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bogdan_nicolesc_3-1643570901781.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17756i29771C2ECF565F31/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bogdan_nicolesc_3-1643570901781.png" alt="bogdan_nicolesc_3-1643570901781.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;How can i tell Splunk to ket data like this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for anyone who reads this time.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jan 2022 19:32:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583033#M102730</guid>
      <dc:creator>bogdan_nicolesc</dc:creator>
      <dc:date>2022-01-30T19:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: Import registry (regedit) data into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583034#M102731</link>
      <description>&lt;P&gt;Idea (untested) from the top of my head - you could use ^\[ as an event breaker. If I remember correctly though, it will consume the opening square parenthesis so the event will be a bit "ugly".&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jan 2022 19:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583034#M102731</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-01-30T19:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Import registry (regedit) data into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583056#M102735</link>
      <description>&lt;P&gt;It is not clear whether the S_N changes for each Key/set of values&lt;/P&gt;&lt;P&gt;Assuming it doesn't and you are working with just the Autologger values, you could try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=Autologger "^(?&amp;lt;sectionKey&amp;gt;\[.*\])$"
| streamstats latest(sectionKey) as sectionKey
| rex field=Autologger "(?&amp;lt;_name&amp;gt;\w+)=(?&amp;lt;_value&amp;gt;.*)"
| eval {_name}=_value
| fields - _name _value Autologger
| stats values(*) as * by sectionKey&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 08:12:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583056#M102735</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-31T08:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Import registry (regedit) data into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583076#M102740</link>
      <description>&lt;P&gt;S/N or S_N, how Splunk rename it, is just a name for serial number that i put it there, in the hope that Splunk would know to get all data of a key and make it into one cassette/cell. What is 1 is a key in registry. Keep in mind that i didn't imported data in Splunk just yet. I'm looking for alteranatives as just how i could import it in Splunk so i can better understand it.&lt;/P&gt;&lt;P&gt;Your code, i assume, would work in search field, right?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;What i was asking was how could i import it better so i can work with it better.&lt;BR /&gt;&lt;BR /&gt;My main questions are:&lt;BR /&gt;&lt;BR /&gt;1. If i put a kind of serial number to all keys, Splunk would know what is what and where it needs to go?&lt;BR /&gt;&lt;BR /&gt;Example:&lt;BR /&gt;&lt;BR /&gt;This is the original file&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\AITEventLog]
"FlushTimer"=dword:00000000
"ClockType"=dword:00000001
"BufferSize"=dword:00000001
"FileMax"=dword:00000005
"MaxFileSize"=dword:00000005
"Guid"="{C0D58A38-5115-43d8-A762-227AC8CA1B5D}"
"FileName"="%SystemRoot%\\System32\\LogFiles\\AIT\\AitEventLog.etl"
"LogFileMode"=dword:01001282
"Start"=dword:00000000
"FileCounter"=dword:00000003
"Status"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\AITEventLog\{6ADDABF4-8C54-4eab-BF4F-FBEF61B62EB0}]
"Enabled"=dword:00000001
"MatchAnyKeyword"=hex(b):00,00,00,00,00,00,00,00
"Status"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Audio]
"GUID"="{15BC788A-6A38-4D79-8773-B53FDFB84D79}"
"FileName"=""
"MaxFileSize"=dword:00000002
"LogFileMode"=dword:10008400
"Start"=dword:00000000
"ClockType"=dword:00000002
"Status"=dword:00000000&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;This would be the serialized file&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;1,[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\AITEventLog]
1,FlushTimer=dword:00000000
1,ClockType=dword:00000001
1,BufferSize=dword:00000001
1,FileMax=dword:00000005
1,MaxFileSize=dword:00000005
1,"Guid=""{C0D58A38-5115-43d8-A762-227AC8CA1B5D}"""
1,"FileName=""%SystemRoot%\\System32\\LogFiles\\AIT\\AitEventLog.etl"""
1,LogFileMode=dword:01001282
1,Start=dword:00000000
1,FileCounter=dword:00000003
1,Status=dword:00000000
,
2,[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\AITEventLog\{6ADDABF4-8C54-4eab-BF4F-FBEF61B62EB0}]
2,Enabled=dword:00000001
2,"MatchAnyKeyword=hex(b):00,00,00,00,00,00,00,00"
2,Status=dword:00000000
,
3,[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Audio]
3,"GUID=""{15BC788A-6A38-4D79-8773-B53FDFB84D79}"""
3,"FileName="""""
3,MaxFileSize=dword:00000002
3,LogFileMode=dword:10008400
3,Start=dword:00000000
3,ClockType=dword:00000002
3,Status=dword:00000000&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;2 If i want to, can i, could i make, let's say "...\AITEventLog]" look more like this type of records?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;20220103111740.000000
Category=12551
CategoryString=Other Logon/Logoff Events
EventCode=4803
EventIdentifier=4803
EventType=4
Logfile=Security
RecordNumber=105722
SourceName=Microsoft-Windows-Security-Auditing
TimeGenerated=20220103091740.977733-000
TimeWritten=20220103091740.977733-000
Type=Audit Success
User=NULL
ComputerName=XXXXXX
wmi_type=WinEventLog:Security
Message=The screen saver was dismissed.&lt;/LI-CODE&gt;&lt;P&gt;And how could i do that? How can i tell Splunk to get data from that file and show i to me like this?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you for your time.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 11:41:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583076#M102740</guid>
      <dc:creator>bogdan_nicolesc</dc:creator>
      <dc:date>2022-01-31T11:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: Import registry (regedit) data into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583085#M102741</link>
      <description>&lt;P&gt;In this case you can separate events with an empty line. Use two line ends as the event breaker.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 13:28:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583085#M102741</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-01-31T13:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: Import registry (regedit) data into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583103#M102744</link>
      <description>&lt;P&gt;It depends on what you are trying to do with the data and how often it changes.&lt;/P&gt;&lt;P&gt;If it doesn't change very much or often, you could load it as a csv file but then you might want to do the transformation I outlined to get all the fields for an event (registry key) on a single line.&lt;/P&gt;&lt;P&gt;If if changes more frequently, and you want to keep previous versions of the file in splunk, you might want to consider ingesting each new version from a new source/file.&lt;/P&gt;&lt;P&gt;Ingesting as a file might allow you to join the lines for a single key into a single event as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;alluded to, although having ingested and indexed it, it is in the index until it is deleted or expires, whereas you could delete and reload the csv if you only want a single copy, but that is more manual effort.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 15:58:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583103#M102744</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-31T15:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Import registry (regedit) data into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583143#M102753</link>
      <description>&lt;P&gt;Where it should go this&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;^\[&amp;nbsp; &amp;nbsp;as it doesn't do anything ...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 21:59:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583143#M102753</guid>
      <dc:creator>bogdan_nicolesc</dc:creator>
      <dc:date>2022-01-31T21:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: Import registry (regedit) data into Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583150#M102754</link>
      <description>&lt;P&gt;Done, i have figure it out. Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something like this i was looking for. If it is correct? I don't know :))&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bogdan_nicolesc_0-1643668352897.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17761i9BD827F216E42555/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bogdan_nicolesc_0-1643668352897.png" alt="bogdan_nicolesc_0-1643668352897.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But! Still is something to work with.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 22:33:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Import-registry-regedit-data-into-Splunk/m-p/583150#M102754</guid>
      <dc:creator>bogdan_nicolesc</dc:creator>
      <dc:date>2022-01-31T22:33:25Z</dc:date>
    </item>
  </channel>
</rss>

