<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help parsing incoming data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672615#M112676</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253046"&gt;@secphilomath1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what technology are you using for these data?&lt;/P&gt;&lt;P&gt;if they are standard, you can use the related add-on that gives you al the parsing rules.&lt;/P&gt;&lt;P&gt;If it's custom, you have t omanually parse it.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 22 Dec 2023 16:23:47 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-12-22T16:23:47Z</dc:date>
    <item>
      <title>Help parsing incoming data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672611#M112674</link>
      <description>&lt;P&gt;We have data coming in that we need to alert on, however because of the formatting of the data, this is very hard to do.&amp;nbsp; &amp;nbsp;The data is coming in as key value pairs but the values are not encapsulated in quotes and is being truncated.&amp;nbsp; For example&lt;/P&gt;&lt;P&gt;_Raw - filepath=c:\program files\abc123\&lt;/P&gt;&lt;P&gt;What we end up getting is&lt;/P&gt;&lt;P&gt;Parsed - filepath=c:\program&lt;/P&gt;&lt;P&gt;Everything after the space is ignored.&lt;/P&gt;&lt;P&gt;If I wanted to find all occurrences where the path was c:\program files\abc123, I can't.&lt;/P&gt;&lt;P&gt;We are sending the data via syslog to the splunk servers&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 15:23:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672611#M112674</guid>
      <dc:creator>secphilomath1</dc:creator>
      <dc:date>2023-12-22T15:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Help parsing incoming data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672615#M112676</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253046"&gt;@secphilomath1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what technology are you using for these data?&lt;/P&gt;&lt;P&gt;if they are standard, you can use the related add-on that gives you al the parsing rules.&lt;/P&gt;&lt;P&gt;If it's custom, you have t omanually parse it.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 16:23:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672615#M112676</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-12-22T16:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: Help parsing incoming data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672617#M112678</link>
      <description>&lt;P&gt;Please share the props and transforms for that sourcetype as well as a couple of sanitized sample events.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 16:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672617#M112678</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-12-22T16:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Help parsing incoming data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672620#M112680</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;The data is coming from a FIM product called Tripwire.&amp;nbsp; Here is the raw data;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;SPAN class=""&gt;Dec&lt;/SPAN&gt; &lt;SPAN class=""&gt;22&lt;/SPAN&gt; &lt;SPAN class=""&gt;02:30:34&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.62.32.10&lt;/SPAN&gt; &lt;SPAN class=""&gt;1&lt;/SPAN&gt; &lt;SPAN class=""&gt;2023-12-22T10:30:34.771Z&lt;/SPAN&gt;&amp;nbsp;servername&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;TW_ES&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;CEF:0&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;Tripwire&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;Enterprise&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;5.5&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;6&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;Audit&lt;/SPAN&gt; &lt;SPAN class=""&gt;Event&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;UserName=NT&lt;/SPAN&gt; &lt;SPAN class=""&gt;AUTHORITY\NETWORK&lt;/SPAN&gt; &lt;SPAN class=""&gt;SERVICE&lt;/SPAN&gt; &lt;SPAN class=""&gt;UserNameLabel=User&lt;/SPAN&gt; &lt;SPAN class=""&gt;Name&lt;/SPAN&gt; &lt;SPAN class=""&gt;ElementName=null&lt;/SPAN&gt; &lt;SPAN class=""&gt;ElementNameLabel=Element&lt;/SPAN&gt; &lt;SPAN class=""&gt;Name&lt;/SPAN&gt; &lt;SPAN class=""&gt;VersionTimeStamp=null&lt;/SPAN&gt; &lt;SPAN class=""&gt;VersionTimeStampLabel=Version&lt;/SPAN&gt; &lt;SPAN class=""&gt;Timestamp&lt;/SPAN&gt; &lt;SPAN class=""&gt;Message=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;C:\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class=""&gt;accessed&lt;/SPAN&gt; &lt;SPAN class=""&gt;by&lt;/SPAN&gt;&lt;SPAN&gt; '&lt;/SPAN&gt;&lt;SPAN class=""&gt;NT&lt;/SPAN&gt; &lt;SPAN class=""&gt;AUTHORITY\NETWORK&lt;/SPAN&gt; &lt;SPAN class=""&gt;SERVICE&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Type&lt;/SPAN&gt;&lt;SPAN&gt; '&lt;/SPAN&gt;&lt;SPAN class=""&gt;Set&lt;/SPAN&gt; &lt;SPAN class=""&gt;Security&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; &lt;SPAN class=""&gt;Application:&lt;/SPAN&gt;&lt;SPAN&gt; '&lt;/SPAN&gt;&lt;SPAN class=""&gt;C:\Windows\System32\svchost.exe&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class=""&gt;Details:&lt;/SPAN&gt; &lt;SPAN class=""&gt;DACL&lt;/SPAN&gt; &lt;SPAN class=""&gt;Category=Audit&lt;/SPAN&gt; &lt;SPAN class=""&gt;Event&lt;/SPAN&gt; &lt;SPAN class=""&gt;CategoryLabel=Category&lt;/SPAN&gt; &lt;SPAN class=""&gt;rt=12/22/23&lt;/SPAN&gt; &lt;SPAN class=""&gt;2:25&lt;/SPAN&gt; &lt;SPAN class=""&gt;AM&lt;/SPAN&gt; &lt;SPAN class=""&gt;Level=Information&lt;/SPAN&gt; &lt;SPAN class=""&gt;LevelLabel=level&lt;/SPAN&gt; &lt;SPAN class=""&gt;dhost=trip.cs.ad.domain.com&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I don't have any props or transforms yet because I am not sure where to start with this.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 16:55:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672620#M112680</guid>
      <dc:creator>secphilomath1</dc:creator>
      <dc:date>2023-12-22T16:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Help parsing incoming data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672641#M112683</link>
      <description>&lt;P&gt;Everything ingested by Splunk should have props.conf settings.&amp;nbsp; Start with the "Great 8": LINE_BREAKER, SHOULD_LINEMERGE, TIME_PREFIX, TIME_FORMAT, MAX_TIMESTAMP_LOOKAHEAD, TRUNCATE, EVENT_BREAKER_ENABLE, and EVENT_BREAKER.&lt;/P&gt;&lt;P&gt;Field extraction from events like this are tricky because the field delimiter is also an allowed character within a field.&amp;nbsp; It means using lookahead to determine if the current character is part of a field name or field value.&amp;nbsp; As it turns out, Splunk is not great with lookahead.&amp;nbsp; Try these settings to see if they work for you.&lt;/P&gt;&lt;P&gt;Props.conf:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[mysourcetype]
SHOULD_LINEMERGE=true
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
TIME_PREFIX=\s\d\s
TIME_FORMAT=%Y-%m-%dT%H:%M:%S.%3N%Z
TRANSFORMS-extract = tripwire_fields
TRUNCATE = 10000
EVENT_BREAKER_ENABLE = true
EVENT_BREAKER = ([\r\n]+)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Transforms.conf:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tripwire_fields]
REGEX = (\w+)=(.*?)(?=\s\w+=)
FORMAT = $1::$2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2023 19:24:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672641#M112683</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-12-28T19:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: Help parsing incoming data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672785#M112689</link>
      <description>&lt;P&gt;Thank you, I think this solved it!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 19:22:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672785#M112689</guid>
      <dc:creator>secphilomath1</dc:creator>
      <dc:date>2023-12-27T19:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Help parsing incoming data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672852#M112695</link>
      <description>&lt;P&gt;Please note: I added a missing "2" at the end of the transforms.conf code.&lt;/P&gt;&lt;P&gt;If your problem is resolved, then please click the "Accept as Solution" button to help future readers.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2023 19:25:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-parsing-incoming-data/m-p/672852#M112695</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-12-28T19:25:15Z</dc:date>
    </item>
  </channel>
</rss>

