<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to separate key loggers from raw log in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/651870#M53467</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I am getting raw log as below:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2023-07-22 09:18:19.454 [INFO ] [Thread-3] AssociationProcessor - compareTransformStatsData : statisticData: StatisticData [selectedDataSet=0, rejectedDataSet=0, totalOutputRecords=19996779, totalInputRecords=0, fileSequenceNum=0, fileHeaderBusDt=null, busDt=07/21/2023, fileName=SETTLEMENT_TRANSFORM_MERGE, totalAchCurrOutstBalAmt=0.0, totalAchBalLastStmtAmt=0.0, totalClosingBal=8.933513237882E10, sourceName=null, version=1, associationStats={}] ---- controlFileData: ControlFileData [fileName=SETTLEMENT_TRANSFORM_ASSOCIATION, busDate=07/21/2023, fileSequenceNum=0, totalBalanceLastStmt=0.0, totalCurrentOutstBal=0.0, totalRecordsWritten=19996779, totalRecords=0, totalClosingBal=8.933513237882E10]&lt;/LI-CODE&gt;&lt;P&gt;I want to show each count separately how can we show that:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;totalOutputRecords=19996779,
totalClosingBal=8.933513237882E10&lt;/LI-CODE&gt;&lt;P&gt;How can we create query like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index= "abc" sourcetype = "600000304_gg_abs_ipc2" "AssociationProcessor&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jul 2023 09:44:59 GMT</pubDate>
    <dc:creator>aditsss</dc:creator>
    <dc:date>2023-07-28T09:44:59Z</dc:date>
    <item>
      <title>How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/651870#M53467</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I am getting raw log as below:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2023-07-22 09:18:19.454 [INFO ] [Thread-3] AssociationProcessor - compareTransformStatsData : statisticData: StatisticData [selectedDataSet=0, rejectedDataSet=0, totalOutputRecords=19996779, totalInputRecords=0, fileSequenceNum=0, fileHeaderBusDt=null, busDt=07/21/2023, fileName=SETTLEMENT_TRANSFORM_MERGE, totalAchCurrOutstBalAmt=0.0, totalAchBalLastStmtAmt=0.0, totalClosingBal=8.933513237882E10, sourceName=null, version=1, associationStats={}] ---- controlFileData: ControlFileData [fileName=SETTLEMENT_TRANSFORM_ASSOCIATION, busDate=07/21/2023, fileSequenceNum=0, totalBalanceLastStmt=0.0, totalCurrentOutstBal=0.0, totalRecordsWritten=19996779, totalRecords=0, totalClosingBal=8.933513237882E10]&lt;/LI-CODE&gt;&lt;P&gt;I want to show each count separately how can we show that:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;totalOutputRecords=19996779,
totalClosingBal=8.933513237882E10&lt;/LI-CODE&gt;&lt;P&gt;How can we create query like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index= "abc" sourcetype = "600000304_gg_abs_ipc2" "AssociationProcessor&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 09:44:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/651870#M53467</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-28T09:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/651875#M53468</link>
      <description>&lt;P&gt;Given that you have asked similar questions before and have been shown how to extract information from log events, what have you tried so far for this scenario?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 11:32:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/651875#M53468</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-25T11:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/651886#M53471</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried but not able to get the correct result can you please guide me here.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 12:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/651886#M53471</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-25T12:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/651895#M53473</link>
      <description>&lt;P&gt;What have you tried?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 12:50:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/651895#M53473</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-25T12:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652196#M53509</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Tried with below query:&lt;/P&gt;&lt;P&gt;index= "abc*" sourcetype = "600000304_gg_abs_ipc2" "Post ASSOCIATION" source="/amex/app/gfp-settlement-transform/logs/gfp-settlement-transform.log" |rex "ASSOCIATION\s+(?&amp;lt;message1&amp;gt;.*)"|table message1 _time&lt;/P&gt;&lt;P&gt;getting below result:&lt;/P&gt;&lt;P&gt;messgae1:&lt;/P&gt;&lt;P&gt;totalInputRecordsCount=19011600, totalOutputRecordsCount=19011598, totalOutstBalFeeAm=8.512726772817E10, nonFinChargeAccounts=17711858, finChargeAccounts=18721170, nonFinCycleAccounts=628, plasticChngAccounts=22298, legalEntityChangeAccounts=0, resv2NonResvAccounts=28, nonresv2ResvAccounts=2694, newAccounts=20663, c2AAccounts=24, acctTermChngCount=155431, excludeAcctCount=0, dailyComputeCount=0, mcaCdChngCount=0, productChngCount=3815&lt;/P&gt;&lt;P&gt;I want to serrate each one of them as I need to show only specific information required like&amp;nbsp;totalInputRecordsCount=19011600, totalOutputRecordsCount=19011598 only these two&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;please guide&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 10:43:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652196#M53509</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-27T10:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652197#M53510</link>
      <description>&lt;P&gt;Based on what your rex command currently does, how would you create a new rex command to find the strings you are interested in (the anchors) and extract the values following the anchors?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 10:43:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652197#M53510</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-27T10:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652209#M53517</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; Is this possible to get only that two result from that query please guide.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 12:10:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652209#M53517</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-27T12:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652239#M53528</link>
      <description>&lt;P&gt;Here is a guide to how the rex command works&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.0/SearchReference/Rex" target="_blank"&gt;rex - Splunk Documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 15:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652239#M53528</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-27T15:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652247#M53530</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am getting current result as below:&lt;/P&gt;&lt;P&gt;index="600000304_d_gridgain_idx*" sourcetype=600000304_gg_abs_ipc2 sourcetype = "600000304_gg_abs_ipc2" "Post ASSOCIATION" source="/amex/app/gfp-settlement-transform/logs/gfp-settlement-transform.log" |rex "Post ASSOCIATION\s+(?&amp;lt;message1&amp;gt;.*)"|table message1 _time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I just show&amp;nbsp; totalInputRecordCount along with the count.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;totalInputRecordsCount =&amp;nbsp;19011600&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26510iC0451DBE3D341E38/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 15:58:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652247#M53530</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-27T15:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652265#M53535</link>
      <description>&lt;P&gt;Explain to me what you think the rex command is doing in your search.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 17:13:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652265#M53535</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-27T17:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652276#M53538</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This Rex command is just giving me all the log after POST ASSOCIATION&lt;/P&gt;&lt;P&gt;But I want only specific information from that logs&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 17:51:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652276#M53538</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-27T17:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652279#M53540</link>
      <description>&lt;P&gt;How exactly does the rex command do that?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 17:59:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652279#M53540</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-27T17:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652283#M53542</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index="600000304_d_gridgain_idx*" sourcetype=600000304_gg_abs_ipc2 sourcetype = "600000304_gg_abs_ipc2" "Post ASSOCIATION" source="/amex/app/gfp-settlement-transform/logs/gfp-settlement-transform.log" |rex "Post ASSOCIATION\s+(?&amp;lt;message1&amp;gt;.*)"|table message1 _time&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The rex command is giving me all results after POST ASSOCIATION but I only want specific information out of it.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 18:35:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652283#M53542</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-27T18:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652291#M53544</link>
      <description>&lt;P&gt;So, if I understand correctly, you are using the rex command without understanding what it does or how you might modify it to get a different result?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 21:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652291#M53544</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-27T21:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652309#M53546</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please guide me how can I use regex to get that expression&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 05:38:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652309#M53546</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-28T05:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652311#M53548</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please help out here to get each of them like InputNumberOf records =189&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 05:49:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652311#M53548</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-07-28T05:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate key loggers from raw log</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652341#M53551</link>
      <description>&lt;P&gt;This is the command you are already using&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|rex "Post ASSOCIATION\s+(?&amp;lt;message1&amp;gt;.*)"&lt;/LI-CODE&gt;&lt;P&gt;You have the _raw log events it is working against&lt;/P&gt;&lt;P&gt;You have the results in the message1 field&lt;/P&gt;&lt;P&gt;You have the documentation for the rex command&lt;/P&gt;&lt;P&gt;You can use use regex101.com as a guide to what the expression is doing and see it working if you paste in your data.&lt;/P&gt;&lt;P&gt;You just need to put a bit of effort into learning what is going on and then try and figure out how to change it to get the new data that you want.&lt;/P&gt;&lt;P&gt;There is a saying about giving fish or teaching how to fish, this is a case of the latter.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 09:22:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-separate-key-loggers-from-raw-log/m-p/652341#M53551</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-28T09:22:54Z</dc:date>
    </item>
  </channel>
</rss>

