<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FortiAnalzer Field Extraction in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/FortiAnalzer-Field-Extraction/m-p/551090#M91499</link>
    <description>&lt;P&gt;No joy I think it is the regex...&lt;/P&gt;</description>
    <pubDate>Mon, 10 May 2021 12:31:08 GMT</pubDate>
    <dc:creator>Rhidian</dc:creator>
    <dc:date>2021-05-10T12:31:08Z</dc:date>
    <item>
      <title>FortiAnalzer Field Extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FortiAnalzer-Field-Extraction/m-p/551075#M91494</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm receiving FortiGate event via FortiAnalyser and I need to set the Host to the name of the device that created the event which is contained in the event message as devname.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;May&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10:44:30&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.90.223.5&lt;/SPAN&gt; &lt;SPAN class="t"&gt;date=2021-05-10&lt;/SPAN&gt; &lt;SPAN class="t"&gt;time=11:44:30&lt;/SPAN&gt; &lt;SPAN class="t"&gt;devname=&lt;/SPAN&gt;&lt;SPAN&gt;"test&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;devid=&lt;/SPAN&gt;&lt;SPAN&gt;"test&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;logid=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0000000013&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;type=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;traffic&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;subtype=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;forward&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;level=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;notice&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;vd=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;root&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;eventtime=1620643470882685981&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tz=&lt;/SPAN&gt;&lt;SPAN&gt;"+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0100&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;srcip=&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;srcport=62408&lt;/SPAN&gt; &lt;SPAN class="t"&gt;srcintf=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;srcintfrole=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;undefined&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;dstip=&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;dstport=53&lt;/SPAN&gt; &lt;SPAN class="t"&gt;dstintf=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;port2&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;dstintfrole=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;wan&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;sessionid=81948384&lt;/SPAN&gt; &lt;SPAN class="t"&gt;proto=17&lt;/SPAN&gt; &lt;SPAN class="t"&gt;action=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;accept&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;policyid=23&lt;/SPAN&gt; &lt;SPAN class="t"&gt;policytype=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;policy&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;poluuid=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;cbd3e37e-5bf1-51eb-f2ad-0a49a47d1d1d&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;service=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Domain&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Services&lt;/SPAN&gt; &lt;SPAN class="t"&gt;UDP&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;dstcountry=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Reserved&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;srccountry=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Reserved&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;trandisp=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;noop&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;duration=180&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sentbyte=76&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rcvdbyte=194&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sentpkt=1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rcvdpkt=1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;vpn=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;vpntype=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;ipsec-dynamic&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;appcat=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;unscanned"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;I have started to build the transform below but it doesn't work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[Set-Host-By-Devname]&lt;/P&gt;&lt;P&gt;REGEX = ([^.+?devname=\"[A-Z0-9]+")&lt;/P&gt;&lt;P&gt;FORMAT = host::$1&lt;/P&gt;&lt;P&gt;DEST_KEY = MetaData:Host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 11:30:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FortiAnalzer-Field-Extraction/m-p/551075#M91494</guid>
      <dc:creator>Rhidian</dc:creator>
      <dc:date>2021-05-10T11:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: FortiAnalzer Field Extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FortiAnalzer-Field-Extraction/m-p/551076#M91495</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231246"&gt;@Rhidian&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you share also your props.conf?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 11:39:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FortiAnalzer-Field-Extraction/m-p/551076#M91495</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-10T11:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: FortiAnalzer Field Extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FortiAnalzer-Field-Extraction/m-p/551079#M91496</link>
      <description>&lt;P&gt;Sure&lt;/P&gt;&lt;P&gt;[fortigate_log]&lt;BR /&gt;TRANSFORMS-Set-Host-By-DevName&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 11:45:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FortiAnalzer-Field-Extraction/m-p/551079#M91496</guid>
      <dc:creator>Rhidian</dc:creator>
      <dc:date>2021-05-10T11:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: FortiAnalzer Field Extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FortiAnalzer-Field-Extraction/m-p/551080#M91497</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231246"&gt;@Rhidian&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try your props like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[fortigate_log]
TRANSFORMS-meta = Set-Host-By-Devname
SHOULD_LINEMERGE = false&lt;/LI-CODE&gt;&lt;P&gt;if doesn't works we need to works on your regex&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 11:52:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FortiAnalzer-Field-Extraction/m-p/551080#M91497</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-10T11:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: FortiAnalzer Field Extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FortiAnalzer-Field-Extraction/m-p/551090#M91499</link>
      <description>&lt;P&gt;No joy I think it is the regex...&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 12:31:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FortiAnalzer-Field-Extraction/m-p/551090#M91499</guid>
      <dc:creator>Rhidian</dc:creator>
      <dc:date>2021-05-10T12:31:08Z</dc:date>
    </item>
  </channel>
</rss>

