<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Props and transforms to strip syslog header from Zeek data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Props-and-transforms-to-strip-syslog-header-from-Zeek-data/m-p/547016#M91076</link>
    <description>&lt;P&gt;It's very difficult to debug a regular expression without sample data.&amp;nbsp; Please provide some.&lt;/P&gt;&lt;P&gt;Consider using the SEDCMD setting in props.conf.&amp;nbsp; It needs no transforms.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SEDCMD-noheader = s/^&amp;lt;\d+&amp;gt;[A-Z][a-z]+\s+\d+\s+\d+:\d+:\d+\s[^\s]*\s\S+:\s//&lt;/LI-CODE&gt;</description>
    <pubDate>Wed, 07 Apr 2021 12:13:09 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-04-07T12:13:09Z</dc:date>
    <item>
      <title>Props and transforms to strip syslog header from Zeek data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-and-transforms-to-strip-syslog-header-from-Zeek-data/m-p/546998#M91071</link>
      <description>&lt;P&gt;I am trying to strip the Syslog header from the Zeek data that I have coming in as the Corelight TA only likes the raw zeek files.&lt;/P&gt;&lt;P&gt;At the moment I have (on a clustered network) -on the indexers in /opt/splunk/etc/system/local the following transforms.conf and below that the props.conf:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;transforms.conf:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[syslog-header-stripper-ts-host]&lt;/P&gt;&lt;P&gt;REGEX = ^&amp;lt;\d+&amp;gt;[A-Z][a-z]+\s+\d+\s+\d+:\d+:\d+\s[^\s]*\s\S+:\s(.*)$&lt;/P&gt;&lt;P&gt;FORMAT = $1&lt;/P&gt;&lt;P&gt;DEST_KEY = _raw&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;props.conf:&lt;/P&gt;&lt;P&gt;[syslog]&lt;/P&gt;&lt;P&gt;# For zeek data - stripping the syslog header&lt;/P&gt;&lt;P&gt;TRANSFORMS-strip-syslog = syslog-header-stripper-ts-host&lt;/P&gt;&lt;P&gt;This doesn't seem to work for the data - as it is still arriving at the Search Heads with the Syslog header on it. Do I need to put these onto the Search Heads instead? Or does the props and transforms need editing?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 09:26:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-and-transforms-to-strip-syslog-header-from-Zeek-data/m-p/546998#M91071</guid>
      <dc:creator>robnewman666</dc:creator>
      <dc:date>2021-04-07T09:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Props and transforms to strip syslog header from Zeek data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-and-transforms-to-strip-syslog-header-from-Zeek-data/m-p/547016#M91076</link>
      <description>&lt;P&gt;It's very difficult to debug a regular expression without sample data.&amp;nbsp; Please provide some.&lt;/P&gt;&lt;P&gt;Consider using the SEDCMD setting in props.conf.&amp;nbsp; It needs no transforms.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SEDCMD-noheader = s/^&amp;lt;\d+&amp;gt;[A-Z][a-z]+\s+\d+\s+\d+:\d+:\d+\s[^\s]*\s\S+:\s//&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 07 Apr 2021 12:13:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-and-transforms-to-strip-syslog-header-from-Zeek-data/m-p/547016#M91076</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-07T12:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: Props and transforms to strip syslog header from Zeek data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-and-transforms-to-strip-syslog-header-from-Zeek-data/m-p/547018#M91077</link>
      <description>&lt;P&gt;Thanks, will give this a try&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 12:17:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-and-transforms-to-strip-syslog-header-from-Zeek-data/m-p/547018#M91077</guid>
      <dc:creator>robnewman666</dc:creator>
      <dc:date>2021-04-07T12:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: Props and transforms to strip syslog header from Zeek data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-and-transforms-to-strip-syslog-header-from-Zeek-data/m-p/547026#M91078</link>
      <description>&lt;P&gt;This did work a treat. Thanks very much!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 12:57:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-and-transforms-to-strip-syslog-header-from-Zeek-data/m-p/547026#M91078</guid>
      <dc:creator>robnewman666</dc:creator>
      <dc:date>2021-04-07T12:57:05Z</dc:date>
    </item>
  </channel>
</rss>

