<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I correctly parse time from the XML field? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-correctly-parse-time-from-the-XML-field/m-p/373777#M109907</link>
    <description>&lt;P&gt;Try without escape chars.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[epo]
SEDCMD-replace = s/\&amp;lt;29\&amp;gt;[^\&amp;gt;]*\&amp;gt;\n*//g
KV_MODE = xml
TIME_PREFIX = &amp;lt;GMTTime&amp;gt;
TIME_FORMAT = %Y-%m-%dT%H:%M:%S
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 18 Aug 2017 16:51:28 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2017-08-18T16:51:28Z</dc:date>
    <item>
      <title>How can I correctly parse time from the XML field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-correctly-parse-time-from-the-XML-field/m-p/373776#M109906</link>
      <description>&lt;P&gt;I am attempting to extract Time using TIME_FORMAT and TIME_PREFIX in props.conf. Would like to understand how to correctly parse the Time from the GMTTime XML field. The original message is read from a file and sent using a universal forwarder. The inputs.conf on the universal forwarder looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///opt/xml/events.txt]
disabled = false
sourcetype = epo
host = lab-epo
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The original message looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;29&amp;gt;1 2017-08-18T02:50:19.0Z LAB-EPO EPOEvents - EventFwd [agentInfo@3401 tenantId="1"] &amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&amp;lt;EPOevent&amp;gt;&amp;lt;MachineInfo&amp;gt;&amp;lt;MachineName&amp;gt;LAB-WIN7-02&amp;lt;/MachineName&amp;gt;&amp;lt;AgentGUID&amp;gt;{b37ff914-XXXX-XXXX-8740-91aa851f0e3d}&amp;lt;/AgentGUID&amp;gt;&amp;lt;IPAddress&amp;gt;192.XXX.XXX.XXX&amp;lt;/IPAddress&amp;gt;&amp;lt;OSName&amp;gt;Windows 7&amp;lt;/OSName&amp;gt;&amp;lt;UserName&amp;gt;SYSTEM&amp;lt;/UserName&amp;gt;&amp;lt;TimeZoneBias&amp;gt;240&amp;lt;/TimeZoneBias&amp;gt;&amp;lt;RawMACAddress&amp;gt;XXXXXXXX&amp;lt;/RawMACAddress&amp;gt;&amp;lt;/MachineInfo&amp;gt;&amp;lt;SoftwareInfo ProductName="McAfee Endpoint Security" ProductVersion="10.5.0" ProductFamily="TVD"&amp;gt;&amp;lt;CommonFields&amp;gt;&amp;lt;Analyzer&amp;gt;ENDP_AM_1050&amp;lt;/Analyzer&amp;gt;&amp;lt;AnalyzerName&amp;gt;McAfee Endpoint Security&amp;lt;/AnalyzerName&amp;gt;&amp;lt;AnalyzerVersion&amp;gt;10.5.0&amp;lt;/AnalyzerVersion&amp;gt;&amp;lt;AnalyzerHostName&amp;gt;LAB-WIN7-02&amp;lt;/AnalyzerHostName&amp;gt;&amp;lt;AnalyzerEngineVersion&amp;gt;XXXX.7806&amp;lt;/AnalyzerEngineVersion&amp;gt;&amp;lt;AnalyzerDetectionMethod&amp;gt;On-Access Scan&amp;lt;/AnalyzerDetectionMethod&amp;gt;&amp;lt;AnalyzerDATVersion&amp;gt;3075.0&amp;lt;/AnalyzerDATVersion&amp;gt;&amp;lt;/CommonFields&amp;gt;&amp;lt;Event&amp;gt;&amp;lt;EventID&amp;gt;1278&amp;lt;/EventID&amp;gt;&amp;lt;Severity&amp;gt;3&amp;lt;/Severity&amp;gt;&amp;lt;GMTTime&amp;gt;2017-08-18T14:48:53&amp;lt;/GMTTime&amp;gt;&amp;lt;CommonFields&amp;gt;&amp;lt;ThreatCategory&amp;gt;av.detect&amp;lt;/ThreatCategory&amp;gt;&amp;lt;ThreatEventID&amp;gt;1278&amp;lt;/ThreatEventID&amp;gt;&amp;lt;ThreatSeverity&amp;gt;2&amp;lt;/ThreatSeverity&amp;gt;&amp;lt;ThreatName&amp;gt;EICAR test file&amp;lt;/ThreatName&amp;gt;&amp;lt;ThreatType&amp;gt;test&amp;lt;/ThreatType&amp;gt;&amp;lt;DetectedUTC&amp;gt;2017-08-18T14:48:53Z&amp;lt;/DetectedUTC&amp;gt;&amp;lt;ThreatActionTaken&amp;gt;IDS_ALERT_ACT_TAK_DEL&amp;lt;/ThreatActionTaken&amp;gt;&amp;lt;ThreatHandled&amp;gt;True&amp;lt;/ThreatHandled&amp;gt;&amp;lt;SourceHostName&amp;gt;LAB-WIN7-02&amp;lt;/SourceHostName&amp;gt;&amp;lt;SourceProcessName&amp;gt;C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE&amp;lt;/SourceProcessName&amp;gt;&amp;lt;TargetHostName&amp;gt;LAB-WIN7-02&amp;lt;/TargetHostName&amp;gt;&amp;lt;TargetUserName&amp;gt;LAB-WIN7-02\xadmin&amp;lt;/TargetUserName&amp;gt;&amp;lt;TargetFileName&amp;gt;C:\USERS\XADMIN\DOWNLOADS\Unconfirmed 408214.crdownload&amp;lt;/TargetFileName&amp;gt;&amp;lt;/CommonFields&amp;gt;&amp;lt;CustomFields target="EPExtendedEventMT"&amp;gt;&amp;lt;BladeName&amp;gt;IDS_BLADE_NAME_SPB&amp;lt;/BladeName&amp;gt;&amp;lt;AnalyzerContentCreationDate&amp;gt;2017-08-16T13:00:00Z&amp;lt;/AnalyzerContentCreationDate&amp;gt;&amp;lt;AnalyzerGTIQuery&amp;gt;False&amp;lt;/AnalyzerGTIQuery&amp;gt;&amp;lt;ThreatDetectedOnCreation&amp;gt;False&amp;lt;/ThreatDetectedOnCreation&amp;gt;&amp;lt;TargetName&amp;gt;Unconfirmed 408214.crdownload&amp;lt;/TargetName&amp;gt;&amp;lt;TargetPath&amp;gt;C:\USERS\XADMIN\DOWNLOADS&amp;lt;/TargetPath&amp;gt;&amp;lt;TargetHash&amp;gt;44d88612fea8a8f36de82e1278abb02f&amp;lt;/TargetHash&amp;gt;&amp;lt;TargetFileSize&amp;gt;68&amp;lt;/TargetFileSize&amp;gt;&amp;lt;TargetModifyTime&amp;gt;2017-08-18T14:48:53Z&amp;lt;/TargetModifyTime&amp;gt;&amp;lt;TargetAccessTime&amp;gt;2017-08-18T14:48:53Z&amp;lt;/TargetAccessTime&amp;gt;&amp;lt;TargetCreateTime&amp;gt;2017-08-18T14:48:53Z&amp;lt;/TargetCreateTime&amp;gt;&amp;lt;Cleanable&amp;gt;False&amp;lt;/Cleanable&amp;gt;&amp;lt;TaskName&amp;gt;IDS_OAS_TASK_NAME&amp;lt;/TaskName&amp;gt;&amp;lt;FirstAttemptedAction&amp;gt;IDS_ALERT_THACT_ATT_CLE&amp;lt;/FirstAttemptedAction&amp;gt;&amp;lt;FirstActionStatus&amp;gt;False&amp;lt;/FirstActionStatus&amp;gt;&amp;lt;SecondAttemptedAction&amp;gt;IDS_ALERT_THACT_ATT_DEL&amp;lt;/SecondAttemptedAction&amp;gt;&amp;lt;SecondActionStatus&amp;gt;True&amp;lt;/SecondActionStatus&amp;gt;&amp;lt;AttackVectorType&amp;gt;4&amp;lt;/AttackVectorType&amp;gt;&amp;lt;DurationBeforeDetection&amp;gt;0&amp;lt;/DurationBeforeDetection&amp;gt;&amp;lt;NaturalLangDescription&amp;gt;IDS_NATURAL_LANG_OAS_DETECTION_DEL|TargetName=Unconfirmed 408214.crdownload|TargetPath=C:\USERS\XADMIN\DOWNLOADS|ThreatName=EICAR test file|SourceProcessName=C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE|ThreatType=test|TargetUserName=LAB-WIN7-02\xadmin&amp;lt;/NaturalLangDescription&amp;gt;&amp;lt;AccessRequested&amp;gt;&amp;lt;/AccessRequested&amp;gt;&amp;lt;DetectionMessage&amp;gt;IDS_OAS_DEFAULT_THREAT_MESSAGE&amp;lt;/DetectionMessage&amp;gt;&amp;lt;AMCoreContentVersion&amp;gt;3075.0&amp;lt;/AMCoreContentVersion&amp;gt;&amp;lt;/CustomFields&amp;gt;&amp;lt;/Event&amp;gt;&amp;lt;/SoftwareInfo&amp;gt;&amp;lt;/EPOevent&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The props.conf on the receiving indexer looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[epo]
SEDCMD-replace = s/\&amp;lt;29\&amp;gt;[^\&amp;gt;]*\&amp;gt;\n*//g
KV_MODE = xml
TIME_PREFIX = \&amp;lt;EPOevent.SoftwareInfo.Event.GMTTime\&amp;gt;
TIME_FORMAT = %Y-%m-%dT%H:%M:%S
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have also tried:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[epo]
SEDCMD-replace = s/\&amp;lt;29\&amp;gt;[^\&amp;gt;]*\&amp;gt;\n*//g
KV_MODE = xml
TIME_PREFIX = \&amp;lt;GMTTime\&amp;gt;
TIME_FORMAT = %Y-%m-%dT%H:%M:%S
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Via search, the event looks like the following after SEC_CMD as parse the message:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;EPOevent&amp;gt;&amp;lt;MachineInfo&amp;gt;&amp;lt;MachineName&amp;gt;LAB-WIN7-02&amp;lt;/MachineName&amp;gt;&amp;lt;AgentGUID&amp;gt;{b37ff914-XXXX-xxxx-XXXX-91aa851fXXXX}&amp;lt;/AgentGUID&amp;gt;&amp;lt;IPAddress&amp;gt;192.xXX.xxx.102&amp;lt;/IPAddress&amp;gt;&amp;lt;OSName&amp;gt;Windows 7&amp;lt;/OSName&amp;gt;&amp;lt;UserName&amp;gt;SYSTEM&amp;lt;/UserName&amp;gt;&amp;lt;TimeZoneBias&amp;gt;240&amp;lt;/TimeZoneBias&amp;gt;&amp;lt;RawMACAddress&amp;gt;000c29xxxxxx&amp;lt;/RawMACAddress&amp;gt;&amp;lt;/MachineInfo&amp;gt;&amp;lt;SoftwareInfo ProductName="McAfee Endpoint Security" ProductVersion="10.5.0" ProductFamily="TVD"&amp;gt;&amp;lt;CommonFields&amp;gt;&amp;lt;Analyzer&amp;gt;ENDP_AM_1050&amp;lt;/Analyzer&amp;gt;&amp;lt;AnalyzerName&amp;gt;McAfee Endpoint Security&amp;lt;/AnalyzerName&amp;gt;&amp;lt;AnalyzerVersion&amp;gt;10.5.0&amp;lt;/AnalyzerVersion&amp;gt;&amp;lt;AnalyzerHostName&amp;gt;LAB-WIN7-02&amp;lt;/AnalyzerHostName&amp;gt;&amp;lt;AnalyzerEngineVersion&amp;gt;5900.7806&amp;lt;/AnalyzerEngineVersion&amp;gt;&amp;lt;AnalyzerDetectionMethod&amp;gt;On-Access Scan&amp;lt;/AnalyzerDetectionMethod&amp;gt;&amp;lt;AnalyzerDATVersion&amp;gt;3075.0&amp;lt;/AnalyzerDATVersion&amp;gt;&amp;lt;/CommonFields&amp;gt;&amp;lt;Event&amp;gt;&amp;lt;EventID&amp;gt;1278&amp;lt;/EventID&amp;gt;&amp;lt;Severity&amp;gt;3&amp;lt;/Severity&amp;gt;&amp;lt;GMTTime&amp;gt;2017-08-18T14:48:53&amp;lt;/GMTTime&amp;gt;&amp;lt;CommonFields&amp;gt;&amp;lt;ThreatCategory&amp;gt;av.detect&amp;lt;/ThreatCategory&amp;gt;&amp;lt;ThreatEventID&amp;gt;1278&amp;lt;/ThreatEventID&amp;gt;&amp;lt;ThreatSeverity&amp;gt;2&amp;lt;/ThreatSeverity&amp;gt;&amp;lt;ThreatName&amp;gt;EICAR test file&amp;lt;/ThreatName&amp;gt;&amp;lt;ThreatType&amp;gt;test&amp;lt;/ThreatType&amp;gt;&amp;lt;DetectedUTC&amp;gt;2017-08-18T14:48:53Z&amp;lt;/DetectedUTC&amp;gt;&amp;lt;ThreatActionTaken&amp;gt;IDS_ALERT_ACT_TAK_DEL&amp;lt;/ThreatActionTaken&amp;gt;&amp;lt;ThreatHandled&amp;gt;True&amp;lt;/ThreatHandled&amp;gt;&amp;lt;SourceHostName&amp;gt;LAB-WIN7-02&amp;lt;/SourceHostName&amp;gt;&amp;lt;SourceProcessName&amp;gt;C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE&amp;lt;/SourceProcessName&amp;gt;&amp;lt;TargetHostName&amp;gt;LAB-WIN7-02&amp;lt;/TargetHostName&amp;gt;&amp;lt;TargetUserName&amp;gt;LAB-WIN7-02\xadmin&amp;lt;/TargetUserName&amp;gt;&amp;lt;TargetFileName&amp;gt;C:\USERS\XADMIN\DOWNLOADS\Unconfirmed 408214.crdownload&amp;lt;/TargetFileName&amp;gt;&amp;lt;/CommonFields&amp;gt;&amp;lt;CustomFields target="EPExtendedEventMT"&amp;gt;&amp;lt;BladeName&amp;gt;IDS_BLADE_NAME_SPB&amp;lt;/BladeName&amp;gt;&amp;lt;AnalyzerContentCreationDate&amp;gt;2017-08-16T13:00:00Z&amp;lt;/AnalyzerContentCreationDate&amp;gt;&amp;lt;AnalyzerGTIQuery&amp;gt;False&amp;lt;/AnalyzerGTIQuery&amp;gt;&amp;lt;ThreatDetectedOnCreation&amp;gt;False&amp;lt;/ThreatDetectedOnCreation&amp;gt;&amp;lt;TargetName&amp;gt;Unconfirmed 408214.crdownload&amp;lt;/TargetName&amp;gt;&amp;lt;TargetPath&amp;gt;C:\USERS\XADMIN\DOWNLOADS&amp;lt;/TargetPath&amp;gt;&amp;lt;TargetHash&amp;gt;44d88612fea8a8f36de82e1278abb02f&amp;lt;/TargetHash&amp;gt;&amp;lt;TargetFileSize&amp;gt;68&amp;lt;/TargetFileSize&amp;gt;&amp;lt;TargetModifyTime&amp;gt;2017-08-18T14:48:53Z&amp;lt;/TargetModifyTime&amp;gt;&amp;lt;TargetAccessTime&amp;gt;2017-08-18T14:48:53Z&amp;lt;/TargetAccessTime&amp;gt;&amp;lt;TargetCreateTime&amp;gt;2017-08-18T14:48:53Z&amp;lt;/TargetCreateTime&amp;gt;&amp;lt;Cleanable&amp;gt;False&amp;lt;/Cleanable&amp;gt;&amp;lt;TaskName&amp;gt;IDS_OAS_TASK_NAME&amp;lt;/TaskName&amp;gt;&amp;lt;FirstAttemptedAction&amp;gt;IDS_ALERT_THACT_ATT_CLE&amp;lt;/FirstAttemptedAction&amp;gt;&amp;lt;FirstActionStatus&amp;gt;False&amp;lt;/FirstActionStatus&amp;gt;&amp;lt;SecondAttemptedAction&amp;gt;IDS_ALERT_THACT_ATT_DEL&amp;lt;/SecondAttemptedAction&amp;gt;&amp;lt;SecondActionStatus&amp;gt;True&amp;lt;/SecondActionStatus&amp;gt;&amp;lt;AttackVectorType&amp;gt;4&amp;lt;/AttackVectorType&amp;gt;&amp;lt;DurationBeforeDetection&amp;gt;0&amp;lt;/DurationBeforeDetection&amp;gt;&amp;lt;NaturalLangDescription&amp;gt;IDS_NATURAL_LANG_OAS_DETECTION_DEL|TargetName=Unconfirmed 408214.crdownload|TargetPath=C:\USERS\XADMIN\DOWNLOADS|ThreatName=EICAR test file|SourceProcessName=C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE|ThreatType=test|TargetUserName=LAB-WIN7-02\xadmin&amp;lt;/NaturalLangDescription&amp;gt;&amp;lt;AccessRequested&amp;gt;&amp;lt;/AccessRequested&amp;gt;&amp;lt;DetectionMessage&amp;gt;IDS_OAS_DEFAULT_THREAT_MESSAGE&amp;lt;/DetectionMessage&amp;gt;
&amp;lt;AMCoreContentVersion&amp;gt;3075.0&amp;lt;/AMCoreContentVersion&amp;gt;&amp;lt;/CustomFields&amp;gt;&amp;lt;/Event&amp;gt;&amp;lt;/SoftwareInfo&amp;gt;&amp;lt;/EPOevent&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The indexer is still applying a timestamp of when it receives the message verse using GMTTime. Here is a formatted view of what splunk sees, e.g. the nested XML:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EPOevent.MachineInfo.AgentGUID
    {b37ff914-83f4-4b48-8740-XXXXXXXXXX}    
EPOevent.MachineInfo.IPAddress
    192.xxx.xxx.XXX 
EPOevent.MachineInfo.MachineName
    LAB-WIN7-02 
EPOevent.MachineInfo.OSName
    Windows 7   
EPOevent.MachineInfo.RawMACAddress
    000c29fXXXXX
EPOevent.MachineInfo.TimeZoneBias
    240 
EPOevent.MachineInfo.UserName
    SYSTEM  
EPOevent.SoftwareInfo.CommonFields.Analyzer
    ENDP_AM_1050    
EPOevent.SoftwareInfo.CommonFields.AnalyzerDATVersion
    3075.0  
EPOevent.SoftwareInfo.CommonFields.AnalyzerDetectionMethod
    On-Access Scan  
EPOevent.SoftwareInfo.CommonFields.AnalyzerEngineVersion
    5900.7806   
EPOevent.SoftwareInfo.CommonFields.AnalyzerHostName
    LAB-WIN7-02 
EPOevent.SoftwareInfo.CommonFields.AnalyzerName
    McAfee Endpoint Security    
EPOevent.SoftwareInfo.CommonFields.AnalyzerVersion
    10.5.0  
EPOevent.SoftwareInfo.Event.CommonFields.DetectedUTC
    2017-08-18T14:48:53Z    
EPOevent.SoftwareInfo.Event.CommonFields.SourceHostName
    LAB-WIN7-02 
EPOevent.SoftwareInfo.Event.CommonFields.SourceProcessName
    C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE 
EPOevent.SoftwareInfo.Event.CommonFields.TargetFileName
    C:\USERS\XADMIN\DOWNLOADS\Unconfirmed 408214.crdownload 
EPOevent.SoftwareInfo.Event.CommonFields.TargetHostName
    LAB-WIN7-02 
EPOevent.SoftwareInfo.Event.CommonFields.TargetUserName
    LAB-WIN7-02\xadmin  
EPOevent.SoftwareInfo.Event.CommonFields.ThreatActionTaken
    IDS_ALERT_ACT_TAK_DEL   
EPOevent.SoftwareInfo.Event.CommonFields.ThreatCategory
    av.detect   
EPOevent.SoftwareInfo.Event.CommonFields.ThreatEventID
    1278    
EPOevent.SoftwareInfo.Event.CommonFields.ThreatHandled
    True    
EPOevent.SoftwareInfo.Event.CommonFields.ThreatName
    EICAR test file 
EPOevent.SoftwareInfo.Event.CommonFields.ThreatSeverity
    2   
EPOevent.SoftwareInfo.Event.CommonFields.ThreatType
    test    
EPOevent.SoftwareInfo.Event.CustomFields.AMCoreContentVersion
    3075.0  
EPOevent.SoftwareInfo.Event.CustomFields.AnalyzerContentCreationDate
    2017-08-16T13:00:00Z    
EPOevent.SoftwareInfo.Event.CustomFields.AnalyzerGTIQuery
    False   
EPOevent.SoftwareInfo.Event.CustomFields.AttackVectorType
    4   
EPOevent.SoftwareInfo.Event.CustomFields.BladeName
    IDS_BLADE_NAME_SPB  
EPOevent.SoftwareInfo.Event.CustomFields.Cleanable
    False   
EPOevent.SoftwareInfo.Event.CustomFields.DetectionMessage
    IDS_OAS_DEFAULT_THREAT_MESSAGE  
EPOevent.SoftwareInfo.Event.CustomFields.DurationBeforeDetection
    0   
EPOevent.SoftwareInfo.Event.CustomFields.FirstActionStatus
    False   
EPOevent.SoftwareInfo.Event.CustomFields.FirstAttemptedAction
    IDS_ALERT_THACT_ATT_CLE 
EPOevent.SoftwareInfo.Event.CustomFields.NaturalLangDescription
    IDS_NATURAL_LANG_OAS_DETECTION_DEL|TargetName=Unconfirmed 408214.crdownload|TargetPath=C:\USERS\XADMIN\DOWNLOADS|ThreatName=EICAR test file|SourceProcessName=C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE|ThreatType=test|TargetUserName=LAB-WIN7-02\xadmin 
EPOevent.SoftwareInfo.Event.CustomFields.SecondActionStatus
    True    
EPOevent.SoftwareInfo.Event.CustomFields.SecondAttemptedAction
    IDS_ALERT_THACT_ATT_DEL 
EPOevent.SoftwareInfo.Event.CustomFields.TargetAccessTime
    2017-08-18T14:48:53Z    
EPOevent.SoftwareInfo.Event.CustomFields.TargetCreateTime
    2017-08-18T14:48:53Z    
EPOevent.SoftwareInfo.Event.CustomFields.TargetFileSize
    68  
EPOevent.SoftwareInfo.Event.CustomFields.TargetHash
    44d88612fea8a8f36de82e1278abb02f    
EPOevent.SoftwareInfo.Event.CustomFields.TargetModifyTime
    2017-08-18T14:48:53Z    
EPOevent.SoftwareInfo.Event.CustomFields.TargetName
    Unconfirmed 408214.crdownload   
EPOevent.SoftwareInfo.Event.CustomFields.TargetPath
    C:\USERS\XADMIN\DOWNLOADS   
EPOevent.SoftwareInfo.Event.CustomFields.TaskName
    IDS_OAS_TASK_NAME   
EPOevent.SoftwareInfo.Event.CustomFields.ThreatDetectedOnCreation
    False   
EPOevent.SoftwareInfo.Event.CustomFields{@target}
    EPExtendedEventMT   
EPOevent.SoftwareInfo.Event.EventID
    1278    
EPOevent.SoftwareInfo.Event.GMTTime
    2017-08-18T14:48:53 
EPOevent.SoftwareInfo.Event.Severity
    3   
EPOevent.SoftwareInfo{@ProductFamily}
    TVD 
EPOevent.SoftwareInfo{@ProductName}
    McAfee Endpoint Security    
EPOevent.SoftwareInfo{@ProductVersion}
    10.5.0  
timestamp
    none    
Time            
_time   
    2017-08-18T10:50:32.000-04:00   
Default 
host
    lab-epo 
index
    main    
linecount
    1   
punct
    &amp;lt;&amp;gt;&amp;lt;&amp;gt;&amp;lt;&amp;gt;--&amp;lt;/&amp;gt;&amp;lt;&amp;gt;{----}&amp;lt;/&amp;gt;&amp;lt;&amp;gt;...&amp;lt;/&amp;gt;&amp;lt;&amp;gt;_&amp;lt;/&amp;gt;&amp;lt;&amp;gt;&amp;lt;/&amp;gt;&amp;lt;&amp;gt;&amp;lt;/&amp;gt;&amp;lt;&amp;gt;&amp;lt;/  
source
    /opt/xml/events.txt     
sourcetype
    epo
splunk_server
    lab-splunk-01
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:24:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-correctly-parse-time-from-the-XML-field/m-p/373776#M109906</guid>
      <dc:creator>rsreese</dc:creator>
      <dc:date>2020-09-29T15:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: How can I correctly parse time from the XML field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-correctly-parse-time-from-the-XML-field/m-p/373777#M109907</link>
      <description>&lt;P&gt;Try without escape chars.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[epo]
SEDCMD-replace = s/\&amp;lt;29\&amp;gt;[^\&amp;gt;]*\&amp;gt;\n*//g
KV_MODE = xml
TIME_PREFIX = &amp;lt;GMTTime&amp;gt;
TIME_FORMAT = %Y-%m-%dT%H:%M:%S
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 18 Aug 2017 16:51:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-correctly-parse-time-from-the-XML-field/m-p/373777#M109907</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-08-18T16:51:28Z</dc:date>
    </item>
  </channel>
</rss>

