<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event Breaking events Zscaler in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/682990#M114039</link>
    <description>&lt;P&gt;#012 here is Line Feed character (\n) escaped by rsyslog (as well as #011 is an escaped \t).&lt;/P&gt;&lt;P&gt;Question is why it's escaped. It would be easiest if the events were broken by rsyslog.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Apr 2024 08:44:30 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-04-03T08:44:30Z</dc:date>
    <item>
      <title>Event Breaking events Zscaler</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/682951#M114037</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I need to event break the following events, but they have a different date format. At the beginning, only at the end, it ends with the 'keyprotectiontype' field, which sometimes has 'NA'. Additionally, it must always have the 'reason' field at the beginning.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Apr 2 22:18:08 04-02 22: 17:39#011reason=Allowed#011event_id=7353490211603742721#011protocol=HTTP#011action=Allowed#011transactionsize=345241#011responsesize=344806#011requestsize=435#011urlcategory=Operating System and Software Updates#011serverip=92.123.121.156#011requestmethod=GET#011refererURL=None#011useragent=Microsoft BITS/7.8#011product=NSS#011location=Road Warrior#011ClientIP=12.2.11.10#011status=206#011user=lvtorrea@lula.com.es#011url=2.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/20c818db-67ad-44d4-8409-4d9dd7986af1?P1=1712128627&amp;amp;P2=404&amp;amp;P3=2&amp;amp;P4=OEkaO+U5XHKvf+lM41oEFDeIKRAD9S6SWgch3BSzA/yxusk1LA44YVdjNg94soDh+D8bYKjPHLpS4296pI6Tcw==#011vendor=Zscaler#011hostname=dkdkdk #011clientpublicIP=1.111.120.11#011threatcategory=None#011threatname=None#011filetype=None#011appname=General Browsing#011pagerisk=0#011threatseverity=None#011department=XXXXX (1422)#011urlsupercategory=Information Technology#011appclass=General Browsing#011dlpengine=None#011urlclass=Business Use#011threatclass=None#011dlpdictionaries=None#011fileclass=None#011bwthrottle=NO#011contenttype=application/octet_stream#011unscannabletype=None#011devicehostname=MAA#011deviceowner=lvtorrea#011keyprotectiontype= Software Protection#0122024-04-02 22:17:39#011reason=Allowed#011event_id=7353490211788947457#011protocol=SSL#011action=Allowed#011transactionsize=9568#011responsesize=4934#011requestsize=4634#011urlcategory=Microsoft_WVD_URL#011serverip=20.189.173.26#011requestmethod=NA#011refererURL=None#011useragent=Unknown#011product=NSS#011location=Road Warrior#011ClientIP=192.168.0.147#011status=NA#011user=jlvaldezo@lula.com.es#011url=us-v10c.events.data.microsoft.com#011vendor=Zscaler#011hostname=dkdkdk#011clientpublicIP=1.19.72.10#011threatcategory=None#011threatname=None#011filetype=None#011appname=General Browsing#011pagerisk=0#011threatseverity=None#011department=xxxxxxx MANAGEMENT#011urlsupercategory=User-defined#011appclass=General Browsing#011dlpengine=None#011urlclass=Bandwidth Loss#011threatclass=None#011dlpdictionaries=None#011fileclass=None#011bwthrottle=NO#011contenttype=Other#011unscannabletype=None#011devicehostname=KDKD#011deviceowner=jlvaldezo#011keyprotectiontype=N/A#012202&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you help me?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 04:42:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/682951#M114037</guid>
      <dc:creator>CarolinaHB</dc:creator>
      <dc:date>2024-04-03T04:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: Event Breaking events Zscaler</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/682954#M114038</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222294"&gt;@CarolinaHB&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I noticed that "#012" exists in your event as end of event marker.&lt;/P&gt;&lt;P&gt;You can use below as a&amp;nbsp;line breaker;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;LINE_BREAKER=#012()&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 04:56:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/682954#M114038</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2024-04-03T04:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: Event Breaking events Zscaler</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/682990#M114039</link>
      <description>&lt;P&gt;#012 here is Line Feed character (\n) escaped by rsyslog (as well as #011 is an escaped \t).&lt;/P&gt;&lt;P&gt;Question is why it's escaped. It would be easiest if the events were broken by rsyslog.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 08:44:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/682990#M114039</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-03T08:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Event Breaking events Zscaler</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/682999#M114040</link>
      <description>&lt;P&gt;It will work but extract with "&lt;EM&gt;#012 ".&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 09:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/682999#M114040</guid>
      <dc:creator>saranvishva</dc:creator>
      <dc:date>2024-04-03T09:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Event Breaking events Zscaler</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/683020#M114041</link>
      <description>&lt;P&gt;I'm by no means an rsyslog guru but ran into it recently.&amp;nbsp; There may be a better way to solve this but the quick fix was to turn off both&amp;nbsp;&lt;A href="https://www.rsyslog.com/doc/configuration/modules/imtcp.html#supportoctetcountedframing" target="_blank" rel="noopener"&gt;supportOctetCountedFraming&lt;/A&gt;&amp;nbsp;(input) and&amp;nbsp;&lt;A href="https://www.rsyslog.com/doc/rainerscript/global.html" target="_blank" rel="noopener"&gt;escapeControlCharacterTab&lt;/A&gt;&amp;nbsp;(global).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="c"&gt;$EscapeControlCharacterTab off

[...other config...]

input(type="imtcp" port="&amp;lt;port&amp;gt;" name="&amp;lt;name&amp;gt;" ruleset="&amp;lt;ruleset&amp;gt;" supportOctetCountedFraming="off")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 13:02:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/683020#M114041</guid>
      <dc:creator>ashurack_qmulos</dc:creator>
      <dc:date>2024-04-03T13:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Event Breaking events Zscaler</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/683036#M114042</link>
      <description>&lt;P&gt;I don't know what is the original rsyslog configuration (and even where that rsyslog is :-)).&lt;/P&gt;&lt;P&gt;But your option will only make the tab character (un)escaped.&lt;/P&gt;&lt;P&gt;The general option for escaping characters is &lt;STRONG&gt;parser.escapeControlCharactersOnReceive&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 13:27:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/683036#M114042</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-03T13:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Event Breaking events Zscaler</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/683044#M114043</link>
      <description>&lt;P&gt;Setting &lt;EM&gt;supportOctetCountedFraming="off"&lt;/EM&gt; on the input fixes newlines being encoded to #012.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 14:31:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/683044#M114043</guid>
      <dc:creator>ashurack_qmulos</dc:creator>
      <dc:date>2024-04-03T14:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Event Breaking events Zscaler</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/683096#M114044</link>
      <description>&lt;P&gt;It does this effect but it works a bit differently. With octet counted option rsyslog split the input connection (because it works with tcp input only) based on the length of the event which should be given at the beginning of the event if I remember correctly. So the main problem is not that the new lines are encoded as #012 but that the events are not split at newline characters as they should be. If you turn of the octet counted option, the incoming tcp stream is broken into separate events on newline character so there is nothing to encode as #012 anymore.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 20:09:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Event-Breaking-events-Zscaler/m-p/683096#M114044</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-03T20:09:58Z</dc:date>
    </item>
  </channel>
</rss>

