<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using Transfroms.conf to drop parts of a file path in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Using-Transfroms-conf-to-drop-parts-of-a-file-path/m-p/544496#M90843</link>
    <description>&lt;P&gt;I am new to using the Transfroms.conf and props.conf to manipulate data. The issue we are experiencing is in our WinEventLog data, we have a field that comes over as Creator Process Name&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Creator&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Process&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Name:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;C:\Program&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Files\SplunkUniversalForwarder\bin\splunkd.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;However most of the correlation searches are looking for process name, parent process name, etc. I have created a field alias to have the Creator Process Name also follow parent process name. I am trying to use Transforms and props in order to drop most of the file path for process name field, for example:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Creator&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Process&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Name:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;C:\Program&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Files\SplunkUniversalForwarder\bin\splunkd.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Process Name: splunkd.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Here is my current entry in Transfroms.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;[Creator_Process_Name_as_process_name]&lt;BR /&gt;SOURCE_KEY = Creator_Process_Name&lt;BR /&gt;REGEX = \t\w:.*[\\](?&amp;lt;process_name&amp;gt;.*)\n&lt;BR /&gt;FORMAT = process_name::$1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;and in Props.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;TRANSFORMS-Creator_Process_Name_as_process_name = Creator_Process_Name_AS_process_name&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Doesn't seem to be working like it should, I actually do get a process name populated but it is the whole flie path. Regex101 seems to show the Regex to be correct in just pulling the .exe&lt;/P&gt;</description>
    <pubDate>Fri, 19 Mar 2021 12:26:54 GMT</pubDate>
    <dc:creator>defikes</dc:creator>
    <dc:date>2021-03-19T12:26:54Z</dc:date>
    <item>
      <title>Using Transfroms.conf to drop parts of a file path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Transfroms-conf-to-drop-parts-of-a-file-path/m-p/544496#M90843</link>
      <description>&lt;P&gt;I am new to using the Transfroms.conf and props.conf to manipulate data. The issue we are experiencing is in our WinEventLog data, we have a field that comes over as Creator Process Name&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Creator&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Process&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Name:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;C:\Program&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Files\SplunkUniversalForwarder\bin\splunkd.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;However most of the correlation searches are looking for process name, parent process name, etc. I have created a field alias to have the Creator Process Name also follow parent process name. I am trying to use Transforms and props in order to drop most of the file path for process name field, for example:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Creator&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Process&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Name:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;C:\Program&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Files\SplunkUniversalForwarder\bin\splunkd.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Process Name: splunkd.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Here is my current entry in Transfroms.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;[Creator_Process_Name_as_process_name]&lt;BR /&gt;SOURCE_KEY = Creator_Process_Name&lt;BR /&gt;REGEX = \t\w:.*[\\](?&amp;lt;process_name&amp;gt;.*)\n&lt;BR /&gt;FORMAT = process_name::$1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;and in Props.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;TRANSFORMS-Creator_Process_Name_as_process_name = Creator_Process_Name_AS_process_name&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Doesn't seem to be working like it should, I actually do get a process name populated but it is the whole flie path. Regex101 seems to show the Regex to be correct in just pulling the .exe&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 12:26:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Transfroms-conf-to-drop-parts-of-a-file-path/m-p/544496#M90843</guid>
      <dc:creator>defikes</dc:creator>
      <dc:date>2021-03-19T12:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: Using Transfroms.conf to drop parts of a file path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Transfroms-conf-to-drop-parts-of-a-file-path/m-p/544502#M90844</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229321"&gt;@defikes&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;In order to drop&amp;nbsp; events which are having&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Process name you can use below props&amp;amp; transfroms.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;props.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TRANSFORMS-dropevents = process_name&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;transforms.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[process_name]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;REGEX =&amp;nbsp;\t\w:.*[\\](.*)\n&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(test your regex before placing here)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 13:20:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Transfroms-conf-to-drop-parts-of-a-file-path/m-p/544502#M90844</guid>
      <dc:creator>Vardhan</dc:creator>
      <dc:date>2021-03-19T13:20:05Z</dc:date>
    </item>
  </channel>
</rss>

