<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Parsing long PowerShell sessions in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-long-PowerShell-sessions/m-p/384808#M69181</link>
    <description>&lt;P&gt;I believe we can potentially link all these events based on the fact that they generate from the same source file.&lt;BR /&gt;
I could probably go back and look up the original user. It just seems to be a cumbersome process.&lt;/P&gt;</description>
    <pubDate>Wed, 29 May 2019 15:29:01 GMT</pubDate>
    <dc:creator>henryyam</dc:creator>
    <dc:date>2019-05-29T15:29:01Z</dc:date>
    <item>
      <title>Parsing long PowerShell sessions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-long-PowerShell-sessions/m-p/384806#M69179</link>
      <description>&lt;P&gt;How is everyone parsing these powershell transcriptions when a person leaves the shell open for multiple days?&lt;BR /&gt;
In that case it shows the user who executed once, but there can be a hundred command starts spanning multiple days.&lt;/P&gt;

&lt;P&gt;Is the consensus to capture this still as one event? Or do you have logic that breaks those into multiple events?&lt;/P&gt;

&lt;P&gt;I have some transcripts files 30+MB in size.&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Command start time: 20190522100828&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;PS&amp;gt;CommandInvocation(Get-ProvTask): "Get-ProvTask"&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;ParameterBinding(Get-ProvTask): name="AdminAddress"; value="google.com:80"&lt;BR /&gt;
ParameterBinding(Get-ProvTask): name="MaxRecordCount"; value="2147483647"&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Command start time: 20190522100830&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;PS&amp;gt;CommandInvocation(Get-BrokerCatalog): "Get-BrokerCatalog"&lt;BR /&gt;
ParameterBinding(Get-BrokerCatalog): name="AdminAddress"; value="yahoo.com:80"&lt;BR /&gt;
ParameterBinding(Get-BrokerCatalog): name="MaxRecordCount"; value="2147483647"&lt;BR /&gt;
ParameterBinding(Get-BrokerCatalog): name="Property"; value="Uid, Name, MetadataMap, ProvisioningSchemeId, Scopes"&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Wed, 22 May 2019 15:21:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-long-PowerShell-sessions/m-p/384806#M69179</guid>
      <dc:creator>henryyam</dc:creator>
      <dc:date>2019-05-22T15:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing long PowerShell sessions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-long-PowerShell-sessions/m-p/384807#M69180</link>
      <description>&lt;P&gt;Converted from answer to a new question.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 17:12:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-long-PowerShell-sessions/m-p/384807#M69180</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-05-22T17:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing long PowerShell sessions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-long-PowerShell-sessions/m-p/384808#M69181</link>
      <description>&lt;P&gt;I believe we can potentially link all these events based on the fact that they generate from the same source file.&lt;BR /&gt;
I could probably go back and look up the original user. It just seems to be a cumbersome process.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 15:29:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-long-PowerShell-sessions/m-p/384808#M69181</guid>
      <dc:creator>henryyam</dc:creator>
      <dc:date>2019-05-29T15:29:01Z</dc:date>
    </item>
  </channel>
</rss>

