<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using regex capture group on a line_breaker attribute for XML parsing of GPO Logs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353324#M104590</link>
    <description>&lt;P&gt;The &lt;CODE&gt;LINE_BREAKER&lt;/CODE&gt; attribute needs a regex capture group.  Try &lt;CODE&gt;LINE_BREAKER = \/GPO&amp;gt;()&lt;/CODE&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Sep 2017 13:04:35 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2017-09-21T13:04:35Z</dc:date>
    <item>
      <title>Using regex capture group on a line_breaker attribute for XML parsing of GPO Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353323#M104589</link>
      <description>&lt;P&gt;I have an XML file, with information regarding Windows GPOs.&lt;/P&gt;

&lt;P&gt;Each Event Looks like the below.&lt;BR /&gt;
The issue is, it is not breaking the data correctly.&lt;BR /&gt;
How should i change the props.conf file so that it always breaks after the last line ""&lt;/P&gt;

&lt;P&gt;I have tried this, but doesn't work (have also tried LINE_BREAKER and also doesn't work):&lt;BR /&gt;
    [source::mysource]&lt;BR /&gt;
     DATETIME_CONFIG = CURRENT&lt;BR /&gt;
     KV_MODE = xml&lt;BR /&gt;
     SHOULD_LINEMERGE =true&lt;BR /&gt;
     MUST_BREAK_AFTER = &amp;lt;\/GPO&amp;gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;GPO xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.microsoft.com/GroupPolicy/Settings"&amp;gt;
  &amp;lt;Identifier&amp;gt;
    &amp;lt;Identifier xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;{3ABBC184-C943-44B8-8C85-EDB5A8AC6E91}&amp;lt;/Identifier&amp;gt;
    &amp;lt;Domain xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;options-it.com&amp;lt;/Domain&amp;gt;
  &amp;lt;/Identifier&amp;gt;
  &amp;lt;Name&amp;gt;Northbay Service Accounts&amp;lt;/Name&amp;gt;
  &amp;lt;IncludeComments&amp;gt;true&amp;lt;/IncludeComments&amp;gt;
  &amp;lt;CreatedTime&amp;gt;2005-11-15T22:46:05&amp;lt;/CreatedTime&amp;gt;
  &amp;lt;ModifiedTime&amp;gt;2017-09-02T02:00:13&amp;lt;/ModifiedTime&amp;gt;
  &amp;lt;ReadTime&amp;gt;2017-09-19T12:35:06.845031Z&amp;lt;/ReadTime&amp;gt;
  &amp;lt;SecurityDescriptor&amp;gt;
    &amp;lt;SDDL xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"&amp;gt;O:DAG:DUD:PAI(OA;CI;CR;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;LCRPRC;;;S-1-5-21-1060284298-1275210071-1417001333-12472)(A;CI;CCDCLCRPWPSDRCWDWO;;;S-1-5-21-1060284298-1275210071-1417001333-22697)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;DA)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;S-1-5-21-1060284298-1275210071-1417001333-519)(A;CI;LCRPLORC;;;ED)(A;CI;LCRPLORC;;;AU)(A;CI;CCDCLCSWRPWPDTLOSDRCWDWO;;;SY)(A;CIIO;CCDCLCSWRPWPDTLOSDRCWDWO;;;CO)S:AI(AU;CIIDSA;CCDCSWWPDTLOCRSDWDWO;;;WD)(AU;CIIDFA;CCDCSWWPDTCRSDWDWO;;;WD)&amp;lt;/SDDL&amp;gt;
    &amp;lt;Owner xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"&amp;gt;
      &amp;lt;SID xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;S-1-5-21-1060284298-1275210071-1417001333-512&amp;lt;/SID&amp;gt;
      &amp;lt;Name xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;OPTIONS-IT\Domain Admins&amp;lt;/Name&amp;gt;
    &amp;lt;/Owner&amp;gt;
    &amp;lt;Group xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"&amp;gt;
      &amp;lt;SID xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;S-1-5-21-1060284298-1275210071-1417001333-513&amp;lt;/SID&amp;gt;
      &amp;lt;Name xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;OPTIONS-IT\Domain Users&amp;lt;/Name&amp;gt;
    &amp;lt;/Group&amp;gt;
    &amp;lt;PermissionsPresent xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"&amp;gt;true&amp;lt;/PermissionsPresent&amp;gt;
    &amp;lt;Permissions xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"&amp;gt;
      &amp;lt;InheritsFromParent&amp;gt;false&amp;lt;/InheritsFromParent&amp;gt;
      &amp;lt;TrusteePermissions&amp;gt;
        &amp;lt;Trustee&amp;gt;
          &amp;lt;SID xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;S-1-5-21-1060284298-1275210071-1417001333-512&amp;lt;/SID&amp;gt;
          &amp;lt;Name xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;OPTIONS-IT\Domain Admins&amp;lt;/Name&amp;gt;
        &amp;lt;/Trustee&amp;gt;
        &amp;lt;Type xsi:type="PermissionType"&amp;gt;
          &amp;lt;PermissionType&amp;gt;Allow&amp;lt;/PermissionType&amp;gt;
        &amp;lt;/Type&amp;gt;
        &amp;lt;Inherited&amp;gt;false&amp;lt;/Inherited&amp;gt;
        &amp;lt;Applicability&amp;gt;
          &amp;lt;ToSelf&amp;gt;true&amp;lt;/ToSelf&amp;gt;
          &amp;lt;ToDescendantObjects&amp;gt;false&amp;lt;/ToDescendantObjects&amp;gt;
          &amp;lt;ToDescendantContainers&amp;gt;true&amp;lt;/ToDescendantContainers&amp;gt;
          &amp;lt;ToDirectDescendantsOnly&amp;gt;false&amp;lt;/ToDirectDescendantsOnly&amp;gt;
        &amp;lt;/Applicability&amp;gt;
        &amp;lt;Standard&amp;gt;
          &amp;lt;GPOGroupedAccessEnum&amp;gt;Edit, delete, modify security&amp;lt;/GPOGroupedAccessEnum&amp;gt;
        &amp;lt;/Standard&amp;gt;
        &amp;lt;AccessMask&amp;gt;0&amp;lt;/AccessMask&amp;gt;
      &amp;lt;/TrusteePermissions&amp;gt;
      &amp;lt;TrusteePermissions&amp;gt;
        &amp;lt;Trustee&amp;gt;
          &amp;lt;SID xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;S-1-5-9&amp;lt;/SID&amp;gt;
          &amp;lt;Name xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS&amp;lt;/Name&amp;gt;
        &amp;lt;/Trustee&amp;gt;
        &amp;lt;Type xsi:type="PermissionType"&amp;gt;
          &amp;lt;PermissionType&amp;gt;Allow&amp;lt;/PermissionType&amp;gt;
        &amp;lt;/Type&amp;gt;
        &amp;lt;Inherited&amp;gt;false&amp;lt;/Inherited&amp;gt;
        &amp;lt;Applicability&amp;gt;
          &amp;lt;ToSelf&amp;gt;true&amp;lt;/ToSelf&amp;gt;
          &amp;lt;ToDescendantObjects&amp;gt;false&amp;lt;/ToDescendantObjects&amp;gt;
          &amp;lt;ToDescendantContainers&amp;gt;true&amp;lt;/ToDescendantContainers&amp;gt;
          &amp;lt;ToDirectDescendantsOnly&amp;gt;false&amp;lt;/ToDirectDescendantsOnly&amp;gt;
        &amp;lt;/Applicability&amp;gt;
        &amp;lt;Standard&amp;gt;
          &amp;lt;GPOGroupedAccessEnum&amp;gt;Read&amp;lt;/GPOGroupedAccessEnum&amp;gt;
        &amp;lt;/Standard&amp;gt;
        &amp;lt;AccessMask&amp;gt;0&amp;lt;/AccessMask&amp;gt;
      &amp;lt;/TrusteePermissions&amp;gt;
      &amp;lt;TrusteePermissions&amp;gt;
        &amp;lt;Trustee&amp;gt;
          &amp;lt;SID xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;S-1-5-18&amp;lt;/SID&amp;gt;
          &amp;lt;Name xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;NT AUTHORITY\SYSTEM&amp;lt;/Name&amp;gt;
        &amp;lt;/Trustee&amp;gt;
        &amp;lt;Type xsi:type="PermissionType"&amp;gt;
          &amp;lt;PermissionType&amp;gt;Allow&amp;lt;/PermissionType&amp;gt;
        &amp;lt;/Type&amp;gt;
        &amp;lt;Inherited&amp;gt;false&amp;lt;/Inherited&amp;gt;
        &amp;lt;Applicability&amp;gt;
          &amp;lt;ToSelf&amp;gt;true&amp;lt;/ToSelf&amp;gt;
          &amp;lt;ToDescendantObjects&amp;gt;false&amp;lt;/ToDescendantObjects&amp;gt;
          &amp;lt;ToDescendantContainers&amp;gt;true&amp;lt;/ToDescendantContainers&amp;gt;
          &amp;lt;ToDirectDescendantsOnly&amp;gt;false&amp;lt;/ToDirectDescendantsOnly&amp;gt;
        &amp;lt;/Applicability&amp;gt;
        &amp;lt;Standard&amp;gt;
          &amp;lt;GPOGroupedAccessEnum&amp;gt;Edit, delete, modify security&amp;lt;/GPOGroupedAccessEnum&amp;gt;
        &amp;lt;/Standard&amp;gt;
        &amp;lt;AccessMask&amp;gt;0&amp;lt;/AccessMask&amp;gt;
      &amp;lt;/TrusteePermissions&amp;gt;
      &amp;lt;TrusteePermissions&amp;gt;
        &amp;lt;Trustee&amp;gt;
          &amp;lt;SID xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;S-1-5-21-1060284298-1275210071-1417001333-519&amp;lt;/SID&amp;gt;
          &amp;lt;Name xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;OPTIONS-IT\Enterprise Admins&amp;lt;/Name&amp;gt;
        &amp;lt;/Trustee&amp;gt;
        &amp;lt;Type xsi:type="PermissionType"&amp;gt;
          &amp;lt;PermissionType&amp;gt;Allow&amp;lt;/PermissionType&amp;gt;
        &amp;lt;/Type&amp;gt;
        &amp;lt;Inherited&amp;gt;false&amp;lt;/Inherited&amp;gt;
        &amp;lt;Applicability&amp;gt;
          &amp;lt;ToSelf&amp;gt;true&amp;lt;/ToSelf&amp;gt;
          &amp;lt;ToDescendantObjects&amp;gt;false&amp;lt;/ToDescendantObjects&amp;gt;
          &amp;lt;ToDescendantContainers&amp;gt;true&amp;lt;/ToDescendantContainers&amp;gt;
          &amp;lt;ToDirectDescendantsOnly&amp;gt;false&amp;lt;/ToDirectDescendantsOnly&amp;gt;
        &amp;lt;/Applicability&amp;gt;
        &amp;lt;Standard&amp;gt;
          &amp;lt;GPOGroupedAccessEnum&amp;gt;Edit, delete, modify security&amp;lt;/GPOGroupedAccessEnum&amp;gt;
        &amp;lt;/Standard&amp;gt;
        &amp;lt;AccessMask&amp;gt;0&amp;lt;/AccessMask&amp;gt;
      &amp;lt;/TrusteePermissions&amp;gt;
      &amp;lt;TrusteePermissions&amp;gt;
        &amp;lt;Trustee&amp;gt;
          &amp;lt;SID xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;S-1-5-21-1060284298-1275210071-1417001333-12472&amp;lt;/SID&amp;gt;
          &amp;lt;Name xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;OPTIONS-IT\Admins PIPE Domain&amp;lt;/Name&amp;gt;
        &amp;lt;/Trustee&amp;gt;
        &amp;lt;Type xsi:type="PermissionType"&amp;gt;
          &amp;lt;PermissionType&amp;gt;Allow&amp;lt;/PermissionType&amp;gt;
        &amp;lt;/Type&amp;gt;
        &amp;lt;Inherited&amp;gt;false&amp;lt;/Inherited&amp;gt;
        &amp;lt;Applicability&amp;gt;
          &amp;lt;ToSelf&amp;gt;true&amp;lt;/ToSelf&amp;gt;
          &amp;lt;ToDescendantObjects&amp;gt;false&amp;lt;/ToDescendantObjects&amp;gt;
          &amp;lt;ToDescendantContainers&amp;gt;true&amp;lt;/ToDescendantContainers&amp;gt;
          &amp;lt;ToDirectDescendantsOnly&amp;gt;false&amp;lt;/ToDirectDescendantsOnly&amp;gt;
        &amp;lt;/Applicability&amp;gt;
        &amp;lt;Standard&amp;gt;
          &amp;lt;GPOGroupedAccessEnum&amp;gt;Read&amp;lt;/GPOGroupedAccessEnum&amp;gt;
        &amp;lt;/Standard&amp;gt;
        &amp;lt;AccessMask&amp;gt;0&amp;lt;/AccessMask&amp;gt;
      &amp;lt;/TrusteePermissions&amp;gt;
      &amp;lt;TrusteePermissions&amp;gt;
        &amp;lt;Trustee&amp;gt;
          &amp;lt;SID xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;S-1-5-11&amp;lt;/SID&amp;gt;
          &amp;lt;Name xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;NT AUTHORITY\Authenticated Users&amp;lt;/Name&amp;gt;
        &amp;lt;/Trustee&amp;gt;
        &amp;lt;Type xsi:type="PermissionType"&amp;gt;
          &amp;lt;PermissionType&amp;gt;Allow&amp;lt;/PermissionType&amp;gt;
        &amp;lt;/Type&amp;gt;
        &amp;lt;Inherited&amp;gt;false&amp;lt;/Inherited&amp;gt;
        &amp;lt;Applicability&amp;gt;
          &amp;lt;ToSelf&amp;gt;true&amp;lt;/ToSelf&amp;gt;
          &amp;lt;ToDescendantObjects&amp;gt;false&amp;lt;/ToDescendantObjects&amp;gt;
          &amp;lt;ToDescendantContainers&amp;gt;true&amp;lt;/ToDescendantContainers&amp;gt;
          &amp;lt;ToDirectDescendantsOnly&amp;gt;false&amp;lt;/ToDirectDescendantsOnly&amp;gt;
        &amp;lt;/Applicability&amp;gt;
        &amp;lt;Standard&amp;gt;
          &amp;lt;GPOGroupedAccessEnum&amp;gt;Apply Group Policy&amp;lt;/GPOGroupedAccessEnum&amp;gt;
        &amp;lt;/Standard&amp;gt;
        &amp;lt;AccessMask&amp;gt;0&amp;lt;/AccessMask&amp;gt;
      &amp;lt;/TrusteePermissions&amp;gt;
      &amp;lt;TrusteePermissions&amp;gt;
        &amp;lt;Trustee&amp;gt;
          &amp;lt;SID xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;S-1-5-21-1060284298-1275210071-1417001333-22697&amp;lt;/SID&amp;gt;
          &amp;lt;Name xmlns="http://www.microsoft.com/GroupPolicy/Types"&amp;gt;OPTIONS-IT\Admins PIPE Systems Engineers&amp;lt;/Name&amp;gt;
        &amp;lt;/Trustee&amp;gt;
        &amp;lt;Type xsi:type="PermissionType"&amp;gt;
          &amp;lt;PermissionType&amp;gt;Allow&amp;lt;/PermissionType&amp;gt;
        &amp;lt;/Type&amp;gt;
        &amp;lt;Inherited&amp;gt;false&amp;lt;/Inherited&amp;gt;
        &amp;lt;Applicability&amp;gt;
          &amp;lt;ToSelf&amp;gt;true&amp;lt;/ToSelf&amp;gt;
          &amp;lt;ToDescendantObjects&amp;gt;false&amp;lt;/ToDescendantObjects&amp;gt;
          &amp;lt;ToDescendantContainers&amp;gt;true&amp;lt;/ToDescendantContainers&amp;gt;
          &amp;lt;ToDirectDescendantsOnly&amp;gt;false&amp;lt;/ToDirectDescendantsOnly&amp;gt;
        &amp;lt;/Applicability&amp;gt;
        &amp;lt;Standard&amp;gt;
          &amp;lt;GPOGroupedAccessEnum&amp;gt;Edit, delete, modify security&amp;lt;/GPOGroupedAccessEnum&amp;gt;
        &amp;lt;/Standard&amp;gt;
        &amp;lt;AccessMask&amp;gt;0&amp;lt;/AccessMask&amp;gt;
      &amp;lt;/TrusteePermissions&amp;gt;
    &amp;lt;/Permissions&amp;gt;
    &amp;lt;AuditingPresent xmlns="http://www.microsoft.com/GroupPolicy/Types/Security"&amp;gt;false&amp;lt;/AuditingPresent&amp;gt;
  &amp;lt;/SecurityDescriptor&amp;gt;
  &amp;lt;FilterDataAvailable&amp;gt;true&amp;lt;/FilterDataAvailable&amp;gt;
  &amp;lt;Computer&amp;gt;
    &amp;lt;VersionDirectory&amp;gt;6&amp;lt;/VersionDirectory&amp;gt;
    &amp;lt;VersionSysvol&amp;gt;6&amp;lt;/VersionSysvol&amp;gt;
    &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
    &amp;lt;ExtensionData&amp;gt;
      &amp;lt;Extension xmlns:q1="http://www.microsoft.com/GroupPolicy/Settings/Security" xsi:type="q1:SecuritySettings"&amp;gt;
        &amp;lt;q1:Account&amp;gt;
          &amp;lt;q1:Name&amp;gt;LockoutBadCount&amp;lt;/q1:Name&amp;gt;
          &amp;lt;q1:SettingNumber&amp;gt;0&amp;lt;/q1:SettingNumber&amp;gt;
          &amp;lt;q1:Type&amp;gt;Account Lockout&amp;lt;/q1:Type&amp;gt;
        &amp;lt;/q1:Account&amp;gt;
      &amp;lt;/Extension&amp;gt;
      &amp;lt;Name&amp;gt;Security&amp;lt;/Name&amp;gt;
    &amp;lt;/ExtensionData&amp;gt;
  &amp;lt;/Computer&amp;gt;
  &amp;lt;User&amp;gt;
    &amp;lt;VersionDirectory&amp;gt;0&amp;lt;/VersionDirectory&amp;gt;
    &amp;lt;VersionSysvol&amp;gt;0&amp;lt;/VersionSysvol&amp;gt;
    &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
  &amp;lt;/User&amp;gt;
&amp;lt;/GPO&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353323#M104589</guid>
      <dc:creator>smcdonald20</dc:creator>
      <dc:date>2020-09-29T15:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Using regex capture group on a line_breaker attribute for XML parsing of GPO Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353324#M104590</link>
      <description>&lt;P&gt;The &lt;CODE&gt;LINE_BREAKER&lt;/CODE&gt; attribute needs a regex capture group.  Try &lt;CODE&gt;LINE_BREAKER = \/GPO&amp;gt;()&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 13:04:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353324#M104590</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-09-21T13:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Using regex capture group on a line_breaker attribute for XML parsing of GPO Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353325#M104591</link>
      <description>&lt;P&gt;Hi @smcdonald20&lt;/P&gt;

&lt;P&gt;Try this setting:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[your_sourcetype]
SHOULD_LINEMERGE=true
BREAK_ONLY_BEFORE=&amp;lt;GPO\s
KV_MODE=xml
TRUNCATE=999999
DATETIME_CONFIG=CURRENT
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 21 Sep 2017 13:07:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353325#M104591</guid>
      <dc:creator>DMohn</dc:creator>
      <dc:date>2017-09-21T13:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: Using regex capture group on a line_breaker attribute for XML parsing of GPO Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353326#M104592</link>
      <description>&lt;P&gt;Thanks, but this doesn't seem to have worked.&lt;BR /&gt;
Can you confirm if the only thing should need to do is edit the props.conf file and restart splunk?&lt;/P&gt;

&lt;P&gt;Are there any other config files i should be changing?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 13:31:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353326#M104592</guid>
      <dc:creator>smcdonald20</dc:creator>
      <dc:date>2017-09-21T13:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Using regex capture group on a line_breaker attribute for XML parsing of GPO Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353327#M104593</link>
      <description>&lt;P&gt;You have to reingest the data, as the extraction happens on index time (you are using indexed extractions) ...&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 13:49:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353327#M104593</guid>
      <dc:creator>DMohn</dc:creator>
      <dc:date>2017-09-21T13:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Using regex capture group on a line_breaker attribute for XML parsing of GPO Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353328#M104594</link>
      <description>&lt;P&gt;Thank you! this worked!!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 13:53:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-regex-capture-group-on-a-line-breaker-attribute-for-XML/m-p/353328#M104594</guid>
      <dc:creator>smcdonald20</dc:creator>
      <dc:date>2017-09-21T13:53:06Z</dc:date>
    </item>
  </channel>
</rss>

