<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to extract multiple value in field CEF? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/how-to-extract-multiple-value-in-field-CEF/m-p/704780#M10336</link>
    <description>&lt;P&gt;CEF is a fairly annoying format to deal with. It has some part defined one way - as delimited values, and another as key=value pairs. There is an app on Splunkbase for handling CEF events - &lt;A href="https://splunkbase.splunk.com/app/487" target="_blank"&gt;https://splunkbase.splunk.com/app/487&lt;/A&gt; But I don't remember if it's any good TBH.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Nov 2024 21:43:11 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-11-19T21:43:11Z</dc:date>
    <item>
      <title>how to extract multiple value in field CEF?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/how-to-extract-multiple-value-in-field-CEF/m-p/700181#M10334</link>
      <description>&lt;P&gt;hello all&lt;/P&gt;
&lt;P&gt;can help me for this? i get data like this&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;abc=1|productName= SHAMPTS JODAC RL MTV 36X(4X60G);ABC MANIS RL 12X720G;SO KLIN ROSE FRESH LIQ 24X200ML|field23=tip&lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;i want to extract productName but can't extract because value productName not using " "&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;so I'm confused to extract it, I've tried it using the spl command&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;| makemv delim=";" productName&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;but the only result is SHAMPTS JODAC RL MTV 36X(4X60G). the rest doesn't appear.&lt;BR /&gt;and also using regex with the command&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;| makemv tokenizer="(([[:alnum:]]+ )+([[:word:]]+))" productName&lt;/LI-CODE&gt;
&lt;P&gt;but the result is still the same.&lt;/P&gt;
&lt;P&gt;so is there any suggestion so that the value after ; can be extracted?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 17:01:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/how-to-extract-multiple-value-in-field-CEF/m-p/700181#M10334</guid>
      <dc:creator>riposans</dc:creator>
      <dc:date>2024-09-26T17:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: how to extract multiple value in field CEF?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/how-to-extract-multiple-value-in-field-CEF/m-p/700199#M10335</link>
      <description>&lt;P&gt;This question is confusing.&amp;nbsp; The data appears to be delimited by | yet the SPL uses ; as a delimiter.&lt;/P&gt;&lt;P&gt;If the productName field starts after "productName=" and ends before the next | then this command should extract it.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "productName=(?&amp;lt;productName&amp;gt;[^\|]+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 26 Sep 2024 12:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/how-to-extract-multiple-value-in-field-CEF/m-p/700199#M10335</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-09-26T12:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: how to extract multiple value in field CEF?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/how-to-extract-multiple-value-in-field-CEF/m-p/704780#M10336</link>
      <description>&lt;P&gt;CEF is a fairly annoying format to deal with. It has some part defined one way - as delimited values, and another as key=value pairs. There is an app on Splunkbase for handling CEF events - &lt;A href="https://splunkbase.splunk.com/app/487" target="_blank"&gt;https://splunkbase.splunk.com/app/487&lt;/A&gt; But I don't remember if it's any good TBH.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 21:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/how-to-extract-multiple-value-in-field-CEF/m-p/704780#M10336</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-19T21:43:11Z</dc:date>
    </item>
  </channel>
</rss>

