<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regex in transforms.conf in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Regex-in-transforms-conf/m-p/555193#M157586</link>
    <description>&lt;P&gt;I'm trying to get this extraction for the filename to work via transforms.conf but it isn't working. Any ideas?&lt;/P&gt;&lt;P&gt;[My_source_type]&lt;/P&gt;&lt;P&gt;REPORT-file= extract_file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[extract_file]&lt;/P&gt;&lt;P&gt;REGEX =&amp;lt;Data Name='TargetFilename'&amp;gt;.*\\\\(?&amp;lt;file&amp;gt;[\S\s+]*)&amp;lt;\/Data&amp;gt;&lt;/P&gt;&lt;P&gt;FORMAT = file:$3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Event xmlns='omitted&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider Name='Microsoft-Windows-Sysmon' Guid='{omitted}'/&amp;gt;&amp;lt;EventID&amp;gt;2&amp;lt;/EventID&amp;gt;&amp;lt;Version&amp;gt;4&amp;lt;/Version&amp;gt;&amp;lt;Level&amp;gt;4&amp;lt;/Level&amp;gt;&amp;lt;Task&amp;gt;2&amp;lt;/Task&amp;gt;&amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;&amp;lt;Keywords&amp;gt;omitted&amp;lt;/Keywords&amp;gt;&amp;lt;TimeCreated SystemTime='2021-06-09T16:31:46.813927400Z'/&amp;gt;&amp;lt;EventRecordID&amp;gt;947063&amp;lt;/EventRecordID&amp;gt;&amp;lt;Correlation/&amp;gt;&amp;lt;Execution ProcessID='4824' ThreadID='6932'/&amp;gt;&amp;lt;Channel&amp;gt;Microsoft-Windows-Sysmon/Operational&amp;lt;/Channel&amp;gt;&amp;lt;Computer&amp;gt;omitted&amp;lt;/Computer&amp;gt;&amp;lt;Security UserID='S-1-5-18'/&amp;gt;&amp;lt;/System&amp;gt;&amp;lt;EventData&amp;gt;&amp;lt;Data Name='RuleName'&amp;gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='UtcTime'&amp;gt;2021-06-09 16:31:46.813&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ProcessGuid'&amp;gt;{omitted}&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ProcessId'&amp;gt;11932&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Image'&amp;gt;C:\Users\omitted\AppData\Local\Microsoft\Teams\current\Teams.exe&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetFilename'&amp;gt;C:\Users\omitted\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\&lt;STRONG&gt;EJ5T0WEDS801S4OF2UEY.temp&lt;/STRONG&gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='CreationUtcTime'&amp;gt;2020-04-21 21:00:25.187&amp;lt;/Data&amp;gt;&amp;lt;Data Name='PreviousCreationUtcTime'&amp;gt;2021-06-09 16:31:46.802&amp;lt;/Data&amp;gt;&amp;lt;/EventData&amp;gt;&amp;lt;/Event&amp;gt;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jun 2021 22:39:04 GMT</pubDate>
    <dc:creator>TheBravoSierra</dc:creator>
    <dc:date>2021-06-09T22:39:04Z</dc:date>
    <item>
      <title>Regex in transforms.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-in-transforms-conf/m-p/555193#M157586</link>
      <description>&lt;P&gt;I'm trying to get this extraction for the filename to work via transforms.conf but it isn't working. Any ideas?&lt;/P&gt;&lt;P&gt;[My_source_type]&lt;/P&gt;&lt;P&gt;REPORT-file= extract_file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[extract_file]&lt;/P&gt;&lt;P&gt;REGEX =&amp;lt;Data Name='TargetFilename'&amp;gt;.*\\\\(?&amp;lt;file&amp;gt;[\S\s+]*)&amp;lt;\/Data&amp;gt;&lt;/P&gt;&lt;P&gt;FORMAT = file:$3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Event xmlns='omitted&amp;gt;&amp;lt;System&amp;gt;&amp;lt;Provider Name='Microsoft-Windows-Sysmon' Guid='{omitted}'/&amp;gt;&amp;lt;EventID&amp;gt;2&amp;lt;/EventID&amp;gt;&amp;lt;Version&amp;gt;4&amp;lt;/Version&amp;gt;&amp;lt;Level&amp;gt;4&amp;lt;/Level&amp;gt;&amp;lt;Task&amp;gt;2&amp;lt;/Task&amp;gt;&amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;&amp;lt;Keywords&amp;gt;omitted&amp;lt;/Keywords&amp;gt;&amp;lt;TimeCreated SystemTime='2021-06-09T16:31:46.813927400Z'/&amp;gt;&amp;lt;EventRecordID&amp;gt;947063&amp;lt;/EventRecordID&amp;gt;&amp;lt;Correlation/&amp;gt;&amp;lt;Execution ProcessID='4824' ThreadID='6932'/&amp;gt;&amp;lt;Channel&amp;gt;Microsoft-Windows-Sysmon/Operational&amp;lt;/Channel&amp;gt;&amp;lt;Computer&amp;gt;omitted&amp;lt;/Computer&amp;gt;&amp;lt;Security UserID='S-1-5-18'/&amp;gt;&amp;lt;/System&amp;gt;&amp;lt;EventData&amp;gt;&amp;lt;Data Name='RuleName'&amp;gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='UtcTime'&amp;gt;2021-06-09 16:31:46.813&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ProcessGuid'&amp;gt;{omitted}&amp;lt;/Data&amp;gt;&amp;lt;Data Name='ProcessId'&amp;gt;11932&amp;lt;/Data&amp;gt;&amp;lt;Data Name='Image'&amp;gt;C:\Users\omitted\AppData\Local\Microsoft\Teams\current\Teams.exe&amp;lt;/Data&amp;gt;&amp;lt;Data Name='TargetFilename'&amp;gt;C:\Users\omitted\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\&lt;STRONG&gt;EJ5T0WEDS801S4OF2UEY.temp&lt;/STRONG&gt;&amp;lt;/Data&amp;gt;&amp;lt;Data Name='CreationUtcTime'&amp;gt;2020-04-21 21:00:25.187&amp;lt;/Data&amp;gt;&amp;lt;Data Name='PreviousCreationUtcTime'&amp;gt;2021-06-09 16:31:46.802&amp;lt;/Data&amp;gt;&amp;lt;/EventData&amp;gt;&amp;lt;/Event&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 22:39:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-in-transforms-conf/m-p/555193#M157586</guid>
      <dc:creator>TheBravoSierra</dc:creator>
      <dc:date>2021-06-09T22:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Regex in transforms.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-in-transforms-conf/m-p/555216#M157595</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230424"&gt;@TheBravoSierra&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Can you check if the following works?&lt;BR /&gt;&amp;lt;Data Name='TargetFilename'&amp;gt;.*\\(?&amp;lt;file&amp;gt;[\S\s+]*)&amp;lt;\/Data&amp;gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 04:45:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-in-transforms-conf/m-p/555216#M157595</guid>
      <dc:creator>t_shreya</dc:creator>
      <dc:date>2021-06-10T04:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Regex in transforms.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-in-transforms-conf/m-p/555221#M157597</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230424"&gt;@TheBravoSierra&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[My_source_type]
REPORT-file= extract_file

[extract_file]
REGEX = \&amp;lt;Data Name\=\'TargetFilename\'\&amp;gt;.*\\(?&amp;lt;file&amp;gt;[^&amp;lt;]+)
FORMAT = file::$1&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rex_test.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14565iC0E5FA4C835DC82F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rex_test.PNG" alt="rex_test.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 05:27:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-in-transforms-conf/m-p/555221#M157597</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-10T05:27:53Z</dc:date>
    </item>
  </channel>
</rss>

