<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Field extraction from checkpoint log with two hostname values in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-checkpoint-log-with-two-hostname-values/m-p/531380#M150098</link>
    <description>&lt;P&gt;Hi! im traying to extract a field named hostname from checkpoint logs, but i couldn't with the wizards:&lt;/P&gt;&lt;P&gt;sample:&lt;/P&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;time=1606760596&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;hostname=CHKHOST&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;product=Mobile&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Access&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;action=Log&lt;/SPAN&gt; &lt;SPAN class="t"&gt;In&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;ifdir=inbound&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;loguid=&lt;/SPAN&gt;{&lt;SPAN class="t"&gt;0x5fc53894&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0x0&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0x250a000a&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0x2e9b&lt;/SPAN&gt;}|&lt;SPAN class="t"&gt;origin=10.0.X.X&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;originsicname=CN\=FW01&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;O\=CHKHOST.localdomain&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;sequencenum=293&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;time=1606760596&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;version=5&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;auth_encryption_methods=AES-256&lt;/SPAN&gt; + &lt;SPAN class="t"&gt;SHA1&lt;/SPAN&gt; + &lt;SPAN class="t"&gt;Group&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;auth_method=RADIUS&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;client_build=986100611&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;client_name=Endpoint&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Security&lt;/SPAN&gt; &lt;SPAN class="t"&gt;VPN&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;client_version=E81.10&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;cvpn_category=Session&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;device_identification=&lt;/SPAN&gt;{&lt;SPAN class="t"&gt;85FAD095-E5AB-43BA-AA8C-B205F783226E&lt;/SPAN&gt;}|&lt;SPAN class="t"&gt;domain_name=localdomain&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;event_type=Login&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;failed_login_factor_num=0&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;host_ip=192.168.X.X&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;host_type=PC&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;hostname=NB-0237&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;lastupdatetime=1606760596&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;login_option=Standard&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;login_timestamp=1606760596&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;mac_address=40:5b:d8:64:5b:29&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;methods:=3DES&lt;/SPAN&gt; + &lt;SPAN class="t"&gt;SHA1&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;office_mode_ip=10.193.0.89&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;os_bits=64bit&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;os_build=18363&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;os_edition=Enterprise&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;os_name=Windows&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;os_version=10&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;proto=6&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;proxy_src_ip=0.0.0.0&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;s_port=0&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;service=443&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;session_timeout=43200&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;session_uid=&lt;/SPAN&gt;{&lt;SPAN class="t"&gt;5FC53894-0000-0000-0A00-0A259B2E0000&lt;/SPAN&gt;}|&lt;SPAN class="t"&gt;src=181.121.X.X&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;status=Success&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;suppressed_logs=0&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;tunnel_protocol=IPSec&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;user=agimenez&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;user_dn=agimenez&lt;/SPAN&gt;|&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;user_group=VPN&lt;/SPAN&gt;_&lt;SPAN class="t"&gt;Group|&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;if you see there are two hostname fields, one with the checkpoint hostname and the other with the device connecting to the vpn. I need the second value.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;In smart mode or verbose mode, splunk only detects the first hostname field.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;How can i parse the second field? Ive tried field extraction wizard with regular expression only selecting the second hostname and i get this error:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;The extraction failed. If you are extracting multiple fields, try removing one or more fields. Start with extractions that are embedded within longer text strings. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;When i try using delimieters, selecting pipe, i get this error:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;has exceeded the configured depth_limit, consider raising the value in limits.conf. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;any help would be appreciated.&lt;/DIV&gt;</description>
    <pubDate>Mon, 30 Nov 2020 19:09:54 GMT</pubDate>
    <dc:creator>dieguiariel</dc:creator>
    <dc:date>2020-11-30T19:09:54Z</dc:date>
    <item>
      <title>Field extraction from checkpoint log with two hostname values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-checkpoint-log-with-two-hostname-values/m-p/531380#M150098</link>
      <description>&lt;P&gt;Hi! im traying to extract a field named hostname from checkpoint logs, but i couldn't with the wizards:&lt;/P&gt;&lt;P&gt;sample:&lt;/P&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;time=1606760596&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;hostname=CHKHOST&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;product=Mobile&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Access&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;action=Log&lt;/SPAN&gt; &lt;SPAN class="t"&gt;In&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;ifdir=inbound&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;loguid=&lt;/SPAN&gt;{&lt;SPAN class="t"&gt;0x5fc53894&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0x0&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0x250a000a&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;0x2e9b&lt;/SPAN&gt;}|&lt;SPAN class="t"&gt;origin=10.0.X.X&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;originsicname=CN\=FW01&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;O\=CHKHOST.localdomain&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;sequencenum=293&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;time=1606760596&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;version=5&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;auth_encryption_methods=AES-256&lt;/SPAN&gt; + &lt;SPAN class="t"&gt;SHA1&lt;/SPAN&gt; + &lt;SPAN class="t"&gt;Group&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;auth_method=RADIUS&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;client_build=986100611&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;client_name=Endpoint&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Security&lt;/SPAN&gt; &lt;SPAN class="t"&gt;VPN&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;client_version=E81.10&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;cvpn_category=Session&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;device_identification=&lt;/SPAN&gt;{&lt;SPAN class="t"&gt;85FAD095-E5AB-43BA-AA8C-B205F783226E&lt;/SPAN&gt;}|&lt;SPAN class="t"&gt;domain_name=localdomain&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;event_type=Login&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;failed_login_factor_num=0&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;host_ip=192.168.X.X&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;host_type=PC&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;hostname=NB-0237&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;lastupdatetime=1606760596&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;login_option=Standard&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;login_timestamp=1606760596&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;mac_address=40:5b:d8:64:5b:29&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;methods:=3DES&lt;/SPAN&gt; + &lt;SPAN class="t"&gt;SHA1&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;office_mode_ip=10.193.0.89&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;os_bits=64bit&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;os_build=18363&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;os_edition=Enterprise&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;os_name=Windows&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;os_version=10&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;proto=6&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;proxy_src_ip=0.0.0.0&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;s_port=0&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;service=443&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;session_timeout=43200&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;session_uid=&lt;/SPAN&gt;{&lt;SPAN class="t"&gt;5FC53894-0000-0000-0A00-0A259B2E0000&lt;/SPAN&gt;}|&lt;SPAN class="t"&gt;src=181.121.X.X&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;status=Success&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;suppressed_logs=0&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;tunnel_protocol=IPSec&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;user=agimenez&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;user_dn=agimenez&lt;/SPAN&gt;|&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;user_group=VPN&lt;/SPAN&gt;_&lt;SPAN class="t"&gt;Group|&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;if you see there are two hostname fields, one with the checkpoint hostname and the other with the device connecting to the vpn. I need the second value.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;In smart mode or verbose mode, splunk only detects the first hostname field.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;How can i parse the second field? Ive tried field extraction wizard with regular expression only selecting the second hostname and i get this error:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;The extraction failed. If you are extracting multiple fields, try removing one or more fields. Start with extractions that are embedded within longer text strings. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;When i try using delimieters, selecting pipe, i get this error:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;has exceeded the configured depth_limit, consider raising the value in limits.conf. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;any help would be appreciated.&lt;/DIV&gt;</description>
      <pubDate>Mon, 30 Nov 2020 19:09:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-checkpoint-log-with-two-hostname-values/m-p/531380#M150098</guid>
      <dc:creator>dieguiariel</dc:creator>
      <dc:date>2020-11-30T19:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction from checkpoint log with two hostname values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-checkpoint-log-with-two-hostname-values/m-p/531389#M150099</link>
      <description>&lt;P&gt;Try using rex.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... | rex max_match=2 "hostname=(?&amp;lt;hostname&amp;gt;[^\|]+)"
| eval hostname=mvindex(hostname,1)
...&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 30 Nov 2020 19:27:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-checkpoint-log-with-two-hostname-values/m-p/531389#M150099</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-30T19:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction from checkpoint log with two hostname values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-checkpoint-log-with-two-hostname-values/m-p/531394#M150103</link>
      <description>&lt;P&gt;Thank you!!! it works perfectly!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 19:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-extraction-from-checkpoint-log-with-two-hostname-values/m-p/531394#M150103</guid>
      <dc:creator>dieguiariel</dc:creator>
      <dc:date>2020-11-30T19:56:09Z</dc:date>
    </item>
  </channel>
</rss>

