<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SEDCMD Help in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554903#M91924</link>
    <description>&lt;P&gt;that captures everything afterwards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ldnail_at_TI_0-1623158084281.png" style="width: 769px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14535iABCA54CEA4AB69B1/image-dimensions/769x100?v=v2" width="769" height="100" role="button" title="ldnail_at_TI_0-1623158084281.png" alt="ldnail_at_TI_0-1623158084281.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Tue, 08 Jun 2021 13:18:13 GMT</pubDate>
    <dc:creator>ldnail_at_TI</dc:creator>
    <dc:date>2021-06-08T13:18:13Z</dc:date>
    <item>
      <title>SEDCMD Help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554753#M91914</link>
      <description>&lt;P&gt;I am attempting to use SEDCMD on ingest to eliminate extra "data" from my logs (and license). This will be running on Heavy Forwarder. Turns out SEDCMD only works on _raw during ingest which is complicated with the Palo TA as it separates CONFIG, THREAT, TRAFFIC, etc.. into their own sourcetypes, so I have to operate off of sourcetype=pan:log which looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Jan 7 10:19:47 palohost 1,2021/06/07: 15:19:46,011901036309,GLOBALPROTECT,...
Jan 7 10:19:47 palohost 1,2021/06/07: 15:19:46,011901036309,HIPMATCH,...
Jan 7 10:19:47 palohost 1,2021/06/07: 15:19:46,011901036309,CONFIG,...
Jan 7 10:19:47 palohost 1,2021/06/07: 15:19:46,011901036309,THREAT,...
Jan 7 10:19:47 palohost 1,2021/06/07: 15:19:46,011901036309,TRAFFIC,...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to perform the SEDCMD only on lines with a TRAFFIC in the 4th field, which I can identify just fine with:&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;^(?:[^,]*,){3}TRAFFIC&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The challenge begins here. I need to capture the first field, which is from start of the line up to the first comma. So for this line:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Jan 7 10:19:47 palohost 1,2021/06/07: 15:19:46,011901036309,TRAFFIC,...&lt;/P&gt;&lt;P&gt;I only want to capture&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Jan 7 10:19:47 palohost 1&lt;/P&gt;&lt;P&gt;Any advise?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 18:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554753#M91914</guid>
      <dc:creator>ldnail_at_TI</dc:creator>
      <dc:date>2021-06-07T18:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: SEDCMD Help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554813#M91915</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/178453"&gt;@ldnail_at_TI&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[YOUR_SOURCE_TYPE]
SEDCMD-a = s/,(.*)TRAFFIC,(.*)$//g
.
.
.&lt;/LI-CODE&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 03:58:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554813#M91915</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-08T03:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: SEDCMD Help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554903#M91924</link>
      <description>&lt;P&gt;that captures everything afterwards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ldnail_at_TI_0-1623158084281.png" style="width: 769px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14535iABCA54CEA4AB69B1/image-dimensions/769x100?v=v2" width="769" height="100" role="button" title="ldnail_at_TI_0-1623158084281.png" alt="ldnail_at_TI_0-1623158084281.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 13:18:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554903#M91924</guid>
      <dc:creator>ldnail_at_TI</dc:creator>
      <dc:date>2021-06-08T13:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: SEDCMD Help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554909#M91925</link>
      <description>&lt;P&gt;ok&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/178453"&gt;@ldnail_at_TI&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is your expected OP from above screen?&lt;/P&gt;&lt;P&gt;KV&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 13:44:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554909#M91925</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-08T13:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: SEDCMD Help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554912#M91926</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;ok&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/178453"&gt;@ldnail_at_TI&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is your expected OP from above screen?&lt;/P&gt;&lt;P&gt;KV&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;"&amp;nbsp; &amp;nbsp;I only want to capture&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;FONT color="#800000"&gt;Jan 7 10:19:47 palohost 1&lt;/FONT&gt;&lt;BR /&gt;"&lt;BR /&gt;which would then be deleted in sedcmd&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 13:48:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554912#M91926</guid>
      <dc:creator>ldnail_at_TI</dc:creator>
      <dc:date>2021-06-08T13:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: SEDCMD Help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554917#M91928</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/178453"&gt;@ldnail_at_TI&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SEDCMD-a = s/,(.*)TRAFFIC,(.*)$//g&lt;/LI-CODE&gt;&lt;P&gt;will give you below results.&lt;/P&gt;&lt;P&gt;Note. &amp;nbsp;This configuration will work with new coming event only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-06-08 at 7.36.42 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14537i5542F9308217E7F3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2021-06-08 at 7.36.42 PM.png" alt="Screenshot 2021-06-08 at 7.36.42 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have used this sample event.&lt;/P&gt;&lt;LI-CODE lang="cpp"&gt;Jan 7 10:19:47 palohost 1,2021/06/07: 15:19:46,011901036309,GLOBALPROTECT,...
Jan 7 10:19:47 palohost 1,2021/06/07: 15:19:46,011901036309,HIPMATCH,...
Jan 7 10:19:47 palohost 1,2021/06/07: 15:19:46,011901036309,CONFIG,...
Jan 7 10:19:47 palohost 1,2021/06/07: 15:19:46,011901036309,THREAT,...
Jan 7 10:19:47 palohost 1,2021/06/07: 15:19:46,011901036309,TRAFFIC,...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 14:08:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554917#M91928</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-08T14:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: SEDCMD Help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554947#M91935</link>
      <description>&lt;P&gt;Thats pretty much the same result as the last and its trips everything but the first field. Results with your SEDCMD&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN class="formated-time"&gt;&lt;SPAN&gt;5/28/21&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3:32:29.100 PM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="json-event  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN class="t"&gt;May&lt;/SPAN&gt; &lt;SPAN class="t"&gt;28&lt;/SPAN&gt; &lt;SPAN class="t"&gt;15:32:30&lt;/SPAN&gt;&amp;nbsp;palohost 1&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="shared-eventsviewer-list-body-row-selectedfields"&gt;&lt;UL class="condensed-selected-fields"&gt;&lt;LI&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN class="field"&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value a"&gt;&lt;A title="pdq" href="https://lincoln.itg.ti.com/en-US/app/search/search?q=search%20source%3D%22ilevpnpantest01-0528-15.log%22%20host%3D%22pdq%22%20index%3D%22adhoc%22%20sourcetype%3D%22pan%3Alog%22&amp;amp;earliest=0&amp;amp;latest=&amp;amp;sid=1623174104.148&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=#" target="_blank" rel="noopener"&gt;pdq&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN class="field"&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value a"&gt;&lt;A title="ilevpnpantest01-0528-15.log" href="https://lincoln.itg.ti.com/en-US/app/search/search?q=search%20source%3D%22ilevpnpantest01-0528-15.log%22%20host%3D%22pdq%22%20index%3D%22adhoc%22%20sourcetype%3D%22pan%3Alog%22&amp;amp;earliest=0&amp;amp;latest=&amp;amp;sid=1623174104.148&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=#" target="_blank" rel="noopener"&gt;palohost-0528-15.log&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN class="field"&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value a"&gt;&lt;A title="pan:log" href="https://lincoln.itg.ti.com/en-US/app/search/search?q=search%20source%3D%22ilevpnpantest01-0528-15.log%22%20host%3D%22pdq%22%20index%3D%22adhoc%22%20sourcetype%3D%22pan%3Alog%22&amp;amp;earliest=0&amp;amp;latest=&amp;amp;sid=1623174104.148&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=#" target="_blank" rel="noopener"&gt;pan:log&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;Source log line:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;May 28 15:32:30&amp;nbsp;palohost 1,2021/05/28: 20:32:29,011901036309,TRAFFIC,end,2305,2021/05/28 20:32:29,&amp;lt;someip&amp;gt;,&amp;lt;someip&amp;gt;,0.0.0.0,0.0.0.0,&amp;lt;rule&amp;gt;,&amp;lt;user&amp;gt;,,&amp;lt;protocol&amp;gt;,&amp;lt;virtualsystem&amp;gt;,EXTTUNNEL,EXTINSIDE,tunnel,ethernet0/0,,,150000,,50000,443,0,0,,tcp,allow,143734,112711,31023,340,2021/05/28 20:30:59,75,&amp;lt;classification&amp;gt;,,,,,,,211,129,&amp;lt;action&amp;gt;,123,456,0,0,,palohost,from-policy,,,0,,0,,N/A,0,0,0,0,&amp;lt;some guid&amp;gt;,0,0,,,,,,,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Here is what I want it to look like without the first field.&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN class="formated-time"&gt;&lt;SPAN&gt;5/28/21&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3:32:29.100 PM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="json-event  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;FONT face="courier new,courier" size="2"&gt;,&lt;SPAN class="t"&gt;2021/05/28:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;20:32:29&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;011901036309&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;TRAFFIC&lt;/SPAN&gt;,end,2305,2021/05/28 20:32:29,&amp;lt;someip&amp;gt;,&amp;lt;someip&amp;gt;,0.0.0.0,0.0.0.0,&amp;lt;rule&amp;gt;,&amp;lt;user&amp;gt;,,&amp;lt;protocol&amp;gt;,&amp;lt;virtualsystem&amp;gt;,EXTTUNNEL,EXTINSIDE,tunnel,ethernet0/0,,,150000,,50000,443,0,0,,tcp,allow,143734,112711,31023,340,2021/05/28 20:30:59,75,&amp;lt;classification&amp;gt;,,,,,,,211,129,&amp;lt;action&amp;gt;,123,456,0,0,,palohost,from-policy,,,0,,0,,N/A,0,0,0,0,&amp;lt;some guid&amp;gt;,0,0,,,,,,,&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="shared-eventsviewer-list-body-row-selectedfields"&gt;&lt;UL class="condensed-selected-fields"&gt;&lt;LI&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN class="field"&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value"&gt;&lt;A title="xxx" href="https://lincoln.itg.ti.com/en-US/app/search/search?q=search%20source%3D%22ilevpnpantest01-0528-15.log%22%20%20index%3D%22adhoc%22&amp;amp;earliest=0&amp;amp;latest=&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;sid=1623174304.156#" target="_blank" rel="noopener"&gt;xxx&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN class="field"&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value a"&gt;&lt;A title="ilevpnpantest01-0528-15.log" href="https://lincoln.itg.ti.com/en-US/app/search/search?q=search%20source%3D%22ilevpnpantest01-0528-15.log%22%20%20index%3D%22adhoc%22&amp;amp;earliest=0&amp;amp;latest=&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;sid=1623174304.156#" target="_blank" rel="noopener"&gt;palohost-0528-15.log&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN class="field"&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value"&gt;&lt;A title="pan:traffic" href="https://lincoln.itg.ti.com/en-US/app/search/search?q=search%20source%3D%22ilevpnpantest01-0528-15.log%22%20%20index%3D%22adhoc%22&amp;amp;earliest=0&amp;amp;latest=&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;sid=1623174304.156#" target="_blank" rel="noopener"&gt;pan:traffic&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 17:57:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/554947#M91935</guid>
      <dc:creator>ldnail_at_TI</dc:creator>
      <dc:date>2021-06-08T17:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: SEDCMD Help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/555019#M91949</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/178453"&gt;@ldnail_at_TI&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this? &lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SEDCMD-a = s/[^,]+(.*TRAFFIC,)/\1 /g&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Screen:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-06-09 at 11.18.30 AM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14553iF5623BD85EDDF797/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2021-06-09 at 11.18.30 AM.png" alt="Screenshot 2021-06-09 at 11.18.30 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 05:49:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SEDCMD-Help/m-p/555019#M91949</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-09T05:49:01Z</dc:date>
    </item>
  </channel>
</rss>

