<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682257#M113982</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258346"&gt;@meetmshah&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not working as expected.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sushraw_0-1711621500691.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29929iC936C6255B2F4995/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sushraw_0-1711621500691.png" alt="sushraw_0-1711621500691.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;search :- log_type=Passed_Authentications MESSAGE_TEXT="Command Authorization succeeded"&amp;nbsp; | rex field=CmdSet max_match=0 "CmdAV=(?&amp;lt;Command&amp;gt;[^\s]+)|\sCmdArgAV=(?&amp;lt;Command1&amp;gt;[^\s]+)" | makemv delim="," allowempty=t Command1 | table _time,Command,Command1&lt;/P&gt;</description>
    <pubDate>Thu, 28 Mar 2024 10:27:42 GMT</pubDate>
    <dc:creator>sushraw</dc:creator>
    <dc:date>2024-03-28T10:27:42Z</dc:date>
    <item>
      <title>add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682126#M113960</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;can someone help me to to extract field 'CmdSet' from cisco ISE accouting logs. string : '[ CmdAV=show CmdArgAV=license CmdArgAV=usage CmdArgAV=&amp;lt;cr&amp;gt; ]'&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 16:31:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682126#M113960</guid>
      <dc:creator>sushraw</dc:creator>
      <dc:date>2024-03-27T16:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682129#M113961</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266356"&gt;@sushraw&lt;/a&gt;, Can you please share sample events in order to create the regex? Sample event along with the field value that you want to extract.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 17:11:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682129#M113961</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2024-03-27T17:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682134#M113962</link>
      <description>&lt;P&gt;TACACS event:&lt;/P&gt;&lt;P&gt;Mar 26 15:37:59 &amp;lt;device_IP&amp;gt; &amp;lt;device_name&amp;gt;_Passed_Authentications 0045846127 2 0 2024-03-26 14:37:59.011 +00:00 06024423114 5202 NOTICE Device-Administration: Command Authorization succeeded, ConfigVersionId=1398, Device IP Address=&amp;lt;device_IP&amp;gt;, DestinationIPAddress=&amp;lt;device_IP&amp;gt;, DestinationPort=49, UserName=&amp;lt;user&amp;gt;, &lt;STRONG&gt;CmdSet=[ CmdAV=show CmdArgAV=running-config CmdArgAV=interface CmdArgAV=Ethernet1/19 CmdArgAV=&amp;lt;cr&amp;gt; ]&lt;/STRONG&gt;, Protocol=Tacacs, MatchedCommandSet=Unsafecommand, RequestLatency=10, NetworkDeviceName=&amp;lt;device_name&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 17:24:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682134#M113962</guid>
      <dc:creator>sushraw</dc:creator>
      <dc:date>2024-03-27T17:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682135#M113963</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266356"&gt;@sushraw&lt;/a&gt;, Can you please try below -&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "CmdSet=\[(?&amp;lt;CmdSet&amp;gt;[^\]]+)\]"&lt;/LI-CODE&gt;&lt;P&gt;The above should extract&amp;nbsp;CmdSet from the events.&lt;/P&gt;&lt;P&gt;If it looks good, you can write search time field extraction to extract the field&amp;nbsp;CmdSet automatically.&lt;/P&gt;&lt;P&gt;Please accept the solution and hit Karma, if this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 17:28:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682135#M113963</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2024-03-27T17:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682146#M113964</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258346"&gt;@meetmshah&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i would like to thank you for your reply.&lt;/P&gt;&lt;P&gt;but i am looking to extract '&lt;STRONG&gt;CmdSet&lt;/STRONG&gt;' field.&lt;/P&gt;&lt;P&gt;i am using 'rex field=CmdSet "CmdAV=(?&amp;lt;Command&amp;gt;[^\s]+)|\sCmdArgAV=(?&amp;lt;Command1&amp;gt;[^\s]+)" '&lt;/P&gt;&lt;P&gt;but it is giving output till 1st CmdArgAV value&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sushraw_0-1711561368589.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29916i1FDF1414D53FFDC3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sushraw_0-1711561368589.png" alt="sushraw_0-1711561368589.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 17:51:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682146#M113964</guid>
      <dc:creator>sushraw</dc:creator>
      <dc:date>2024-03-27T17:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682149#M113965</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266356"&gt;@sushraw&lt;/a&gt;, Can you please try below -&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "CmdSet=\[(?&amp;lt;CmdSet&amp;gt;[^\]]+)\]"
| rex field=CmdSet "CmdArgAV=(?&amp;lt;CmdArgAV&amp;gt;[^\s]+)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please accept the solution and hit Karma, if this helps!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 18:03:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682149#M113965</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2024-03-27T18:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682153#M113966</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258346"&gt;@meetmshah&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your reply. but not working as expected&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sushraw_0-1711563353180.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29917i52E49307930F061D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sushraw_0-1711563353180.png" alt="sushraw_0-1711563353180.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 18:16:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682153#M113966</guid>
      <dc:creator>sushraw</dc:creator>
      <dc:date>2024-03-27T18:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682155#M113967</link>
      <description>&lt;P&gt;Oh we will need to add&amp;nbsp;&lt;SPAN&gt;max_match=0 in rex. Example below -&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "CmdSet=\[(?&amp;lt;CmdSet&amp;gt;[^\]]+)\]"
| rex field=CmdSet max_match=0 "CmdArgAV=(?&amp;lt;CmdArgAV&amp;gt;[^\s]+)"&lt;/LI-CODE&gt;&lt;P&gt;Can you please have a check and me know how it goes?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 18:24:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682155#M113967</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2024-03-27T18:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682224#M113975</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258346"&gt;@meetmshah&lt;/a&gt;thanks 'max_match=0' helped.&lt;/P&gt;&lt;P&gt;but command keywords are separated by 'Enter'. is there any options to keep all words in one line?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sushraw_0-1711598829000.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29927i74E809EE11E7DD71/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sushraw_0-1711598829000.png" alt="sushraw_0-1711598829000.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 04:08:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682224#M113975</guid>
      <dc:creator>sushraw</dc:creator>
      <dc:date>2024-03-28T04:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682227#M113976</link>
      <description>&lt;P&gt;Can you please try appending below -&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makemv delim="," allowempty=t CmdArgAV&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please accept the solution and hit Karma, if this helps!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 05:22:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682227#M113976</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2024-03-28T05:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682257#M113982</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258346"&gt;@meetmshah&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not working as expected.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sushraw_0-1711621500691.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29929iC936C6255B2F4995/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sushraw_0-1711621500691.png" alt="sushraw_0-1711621500691.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;search :- log_type=Passed_Authentications MESSAGE_TEXT="Command Authorization succeeded"&amp;nbsp; | rex field=CmdSet max_match=0 "CmdAV=(?&amp;lt;Command&amp;gt;[^\s]+)|\sCmdArgAV=(?&amp;lt;Command1&amp;gt;[^\s]+)" | makemv delim="," allowempty=t Command1 | table _time,Command,Command1&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 10:27:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682257#M113982</guid>
      <dc:creator>sushraw</dc:creator>
      <dc:date>2024-03-28T10:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: add regular expression for cisco ISE accounting logs CmdAV=show CmdArgAV=license CmdArgAV=usage</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682489#M113995</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266356"&gt;@sushraw&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try appending below -&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makemv CmdArgAV 
| eval CmdArgAV = replace(CmdArgAV, "\n", ", ")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The final results based on the sample event you shared would be -&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval _raw="Mar 26 15:37:59 &amp;lt;device_IP&amp;gt; &amp;lt;device_name&amp;gt;_Passed_Authentications 0045846127 2 0 2024-03-26 14:37:59.011 +00:00 06024423114 5202 NOTICE Device-Administration: Command Authorization succeeded, ConfigVersionId=1398, Device IP Address=&amp;lt;device_IP&amp;gt;, DestinationIPAddress=&amp;lt;device_IP&amp;gt;, DestinationPort=49, UserName=&amp;lt;user&amp;gt;, CmdSet=[ CmdAV=show CmdArgAV=running-config CmdArgAV=interface CmdArgAV=Ethernet1/19 CmdArgAV=&amp;lt;cr&amp;gt; ], Protocol=Tacacs, MatchedCommandSet=Unsafecommand, RequestLatency=10, NetworkDeviceName=&amp;lt;device_name&amp;gt;" 
| rex field=_raw "CmdSet=\[(?&amp;lt;CmdSet&amp;gt;[^\]]+)\]" 
| rex field=CmdSet max_match=0 "CmdArgAV=(?&amp;lt;CmdArgAV&amp;gt;[^\s]+)" 
| makemv CmdArgAV 
| eval CmdArgAV = replace(CmdArgAV, "\n", ", ")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below screenshot for your reference -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KothariSurbhi_0-1711809498250.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29969iBCED06DAEE4F46E0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KothariSurbhi_0-1711809498250.png" alt="KothariSurbhi_0-1711809498250.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this reply helps you, Karma would be appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2024 14:39:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/add-regular-expression-for-cisco-ISE-accounting-logs-CmdAV-show/m-p/682489#M113995</guid>
      <dc:creator>KothariSurbhi</dc:creator>
      <dc:date>2024-03-30T14:39:10Z</dc:date>
    </item>
  </channel>
</rss>

