<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Indexing Ubisecure Ubilogin logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-Ubisecure-Ubilogin-logs/m-p/533157#M89568</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Have anyone indexed Ubisecure's Ubilogin audit or diag files? Basically those are CSV files, BUT depending of event there are different amount of columns even same type of even based on e.g. used authentication method.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;time, src ip, action, user info, f1, f2, f3, f4
t1, src-1, authentication method list, _xyz, "CN=aa,OU=b....", "user agent"
t2, src-1, authentication method list, _xyz, password.xx, "CN=aa,OU=b....", "user agent"
t3, src-1, login, _xyz, yyy, password.xx, "CN=bb, OU=cc...", foo,...,...,..&lt;/LI-CODE&gt;&lt;P&gt;Even same action can contain different amount of fields based on "user info" field.&lt;/P&gt;&lt;P&gt;There are some other actions too.&lt;/P&gt;&lt;P&gt;If there is no better solution then I probably try this: &lt;A href="https://community.splunk.com/t5/Getting-Data-In/Indexing-a-CSV-data-file-with-more-than-one-set-of-data/m-p/40562" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Indexing-a-CSV-data-file-with-more-than-one-set-of-data/m-p/40562&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Dec 2020 14:16:52 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-12-15T14:16:52Z</dc:date>
    <item>
      <title>Indexing Ubisecure Ubilogin logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-Ubisecure-Ubilogin-logs/m-p/533157#M89568</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Have anyone indexed Ubisecure's Ubilogin audit or diag files? Basically those are CSV files, BUT depending of event there are different amount of columns even same type of even based on e.g. used authentication method.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;time, src ip, action, user info, f1, f2, f3, f4
t1, src-1, authentication method list, _xyz, "CN=aa,OU=b....", "user agent"
t2, src-1, authentication method list, _xyz, password.xx, "CN=aa,OU=b....", "user agent"
t3, src-1, login, _xyz, yyy, password.xx, "CN=bb, OU=cc...", foo,...,...,..&lt;/LI-CODE&gt;&lt;P&gt;Even same action can contain different amount of fields based on "user info" field.&lt;/P&gt;&lt;P&gt;There are some other actions too.&lt;/P&gt;&lt;P&gt;If there is no better solution then I probably try this: &lt;A href="https://community.splunk.com/t5/Getting-Data-In/Indexing-a-CSV-data-file-with-more-than-one-set-of-data/m-p/40562" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Indexing-a-CSV-data-file-with-more-than-one-set-of-data/m-p/40562&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 14:16:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-Ubisecure-Ubilogin-logs/m-p/533157#M89568</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-12-15T14:16:52Z</dc:date>
    </item>
  </channel>
</rss>

