<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Regex for multiple lines of a field value in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655612#M111074</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259969"&gt;@RahulMisra&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;could you share a sample of your full logs, not only a part of them?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 25 Aug 2023 09:41:28 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-08-25T09:41:28Z</dc:date>
    <item>
      <title>How to create regex for multiple lines of a field value?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655611#M111073</link>
      <description>&lt;P&gt;I want to extract numeric values into seperate field&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;combinedrules&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; ["&lt;/SPAN&gt;&lt;SPAN class=""&gt;3000039&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;3000081&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;958052&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;973335&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;XSS&lt;/SPAN&gt;-&lt;SPAN class=""&gt;ANOMALY&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;"]&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Expected Output:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Ruleid&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3000039&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3000081&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;958052&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Three&lt;SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;might be a case when there could be 2 rules Id in one event&amp;nbsp;and i wan to see both gets displayed in a&amp;nbsp; single line&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 16:09:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655611#M111073</guid>
      <dc:creator>RahulMisra</dc:creator>
      <dc:date>2023-08-30T16:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for multiple lines of a field value</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655612#M111074</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259969"&gt;@RahulMisra&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;could you share a sample of your full logs, not only a part of them?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 09:41:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655612#M111074</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-08-25T09:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for multiple lines of a field value</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655613#M111075</link>
      <description>&lt;P&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class=""&gt;type&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "testlog&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;configId&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;22269&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;policyId&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;FIST_52163&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;anomali&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "34.87.65.2&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;combinedrules&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; ["&lt;/SPAN&gt;&lt;SPAN class=""&gt;3000039&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;3000081&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;958052&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;973335&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;XSS-ANOMALY&lt;/SPAN&gt;&lt;SPAN&gt;"], "&lt;/SPAN&gt;&lt;SPAN class=""&gt;ruleMessages&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; ["&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cross-site&lt;/SPAN&gt; &lt;SPAN class=""&gt;Scripting&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;XSS&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;Attack&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cross-site&lt;/SPAN&gt; &lt;SPAN class=""&gt;Scripting&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;XSS&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;Attack&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cross-site&lt;/SPAN&gt; &lt;SPAN class=""&gt;Scripting&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;XSS&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;Attack&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Cross-site&lt;/SPAN&gt; &lt;SPAN class=""&gt;Scripting&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;XSS&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;Attack&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Anomaly&lt;/SPAN&gt; &lt;SPAN class=""&gt;Score&lt;/SPAN&gt; &lt;SPAN class=""&gt;Exceeded&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;Cross-site&lt;/SPAN&gt; &lt;SPAN class=""&gt;Scripting&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;XSS&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;Attack&lt;/SPAN&gt;&lt;SPAN&gt;"], "&lt;/SPAN&gt;&lt;SPAN class=""&gt;ruleTags&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; ["&lt;/SPAN&gt;&lt;SPAN class=""&gt;ASE/WEB_ATTACK/XSS&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;ASE/WEB_ATTACK/XSS&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;ASE/WEB_ATTACK/XSS&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;ASE/WEB_ATTACK/XSS&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;ASE/WEB_ATTACK/XSS&lt;/SPAN&gt;&lt;SPAN&gt;"], "&lt;/SPAN&gt;&lt;SPAN class=""&gt;ruleData&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; ["&lt;/SPAN&gt;&lt;SPAN class=""&gt;document.domain&lt;/SPAN&gt;&lt;SPAN&gt;", ")&lt;/SPAN&gt;&lt;SPAN class=""&gt;alert&lt;/SPAN&gt;&lt;SPAN&gt;(", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;alert&lt;/SPAN&gt;&lt;SPAN&gt;(", "')&lt;/SPAN&gt;&lt;SPAN class=""&gt;alert&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;document.domain&lt;/SPAN&gt;&lt;SPAN&gt;)", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Vector&lt;/SPAN&gt; &lt;SPAN class=""&gt;Score:&lt;/SPAN&gt; &lt;SPAN class=""&gt;17&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Group&lt;/SPAN&gt; &lt;SPAN class=""&gt;Threshold:&lt;/SPAN&gt; &lt;SPAN class=""&gt;7&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Triggered&lt;/SPAN&gt; &lt;SPAN class=""&gt;Rules:&lt;/SPAN&gt; &lt;SPAN class=""&gt;3000081-958052-3000039-973335&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Triggered&lt;/SPAN&gt; &lt;SPAN class=""&gt;Scores:&lt;/SPAN&gt; &lt;SPAN class=""&gt;5-5-5-2&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Triggered&lt;/SPAN&gt; &lt;SPAN class=""&gt;Selector:&lt;/SPAN&gt; &lt;SPAN class=""&gt;ARGS:errorCode&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Mitigated&lt;/SPAN&gt; &lt;SPAN class=""&gt;Rules:&lt;/SPAN&gt;&lt;SPAN&gt; , &lt;/SPAN&gt;&lt;SPAN class=""&gt;Last&lt;/SPAN&gt; &lt;SPAN class=""&gt;Matched&lt;/SPAN&gt; &lt;SPAN class=""&gt;Message:&lt;/SPAN&gt;&lt;SPAN&gt; "], "&lt;/SPAN&gt;&lt;SPAN class=""&gt;ruleActions&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; ["&lt;/SPAN&gt;&lt;SPAN class=""&gt;alert&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;alert&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;alert&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;alert&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;deny&lt;/SPAN&gt;&lt;SPAN&gt;"], "&lt;/SPAN&gt;&lt;SPAN class=""&gt;requestId&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;2ed42ca7&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;method&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;GET&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Host&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "test.goodies.com&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;path&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;/carbon/admin/login.jsp&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;User-Agent&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;Windows&lt;/SPAN&gt; &lt;SPAN class=""&gt;NT&lt;/SPAN&gt; &lt;SPAN class=""&gt;5.1&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;AppleWebKit/537.36&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;like&lt;/SPAN&gt; &lt;SPAN class=""&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;Chrome/34.0.1866.237&lt;/SPAN&gt; &lt;SPAN class=""&gt;Safari/537.36&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;status&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;403&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Server&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;AkamaiGHost&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Date&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;Fri&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;25&lt;/SPAN&gt; &lt;SPAN class=""&gt;Aug&lt;/SPAN&gt; &lt;SPAN class=""&gt;2023&lt;/SPAN&gt; &lt;SPAN class=""&gt;09:10:04&lt;/SPAN&gt; &lt;SPAN class=""&gt;GMT&lt;/SPAN&gt;&lt;SPAN&gt;"}&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 09:47:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655613#M111075</guid>
      <dc:creator>RahulMisra</dc:creator>
      <dc:date>2023-08-25T09:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for multiple lines of a field value</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655675#M111088</link>
      <description>&lt;P&gt;Something like this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "combinedrules\: \[(?&amp;lt;Rules&amp;gt;(.*[^(\]\,)?]))"
| rex field=Rules max_match=0 "(?&amp;lt;RuleId&amp;gt;(\d+))"
| stats count by RuleId&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 25 Aug 2023 16:33:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655675#M111088</guid>
      <dc:creator>Thulasinathan_M</dc:creator>
      <dc:date>2023-08-25T16:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for multiple lines of a field value</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655677#M111089</link>
      <description>&lt;P&gt;It's not about a regex as such. It's about the whole props construction.&lt;/P&gt;&lt;P&gt;You have two options.&lt;/P&gt;&lt;P&gt;1. Use one transform to parse out the set of rules contained within brackets and then use another transform with SOURCE_KEY set to your extracted field and MV_ADD=true to further split it up into single values.&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;2. Parse out the whole set within brackets and then define TOKENIZER in fields.conf&lt;/P&gt;&lt;P&gt;The latter approach works with such lists while the first is a bit more generic.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 16:50:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655677#M111089</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-08-25T16:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for multiple lines of a field value</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655929#M111125</link>
      <description>&lt;P&gt;So, we can;t make a regex on search to fetch the fields values ?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 08:45:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-regex-for-multiple-lines-of-a-field-value/m-p/655929#M111125</guid>
      <dc:creator>RahulMisra</dc:creator>
      <dc:date>2023-08-29T08:45:03Z</dc:date>
    </item>
  </channel>
</rss>

