<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Convert audit.log TTY data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74641#M18822</link>
    <description>&lt;P&gt;Running into the same issue, can help mention how to tried to extract field "data" into string format.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Jan 2019 07:18:08 GMT</pubDate>
    <dc:creator>dharshini</dc:creator>
    <dc:date>2019-01-24T07:18:08Z</dc:date>
    <item>
      <title>Convert audit.log TTY data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74637#M18818</link>
      <description>&lt;P&gt;I'm sending my splunk server /var/log/audit.log data from each client machine (splunkforwarder). I have logging of TTY data for root enabled, and would like to be able to read that in splunk. Does anyone know a way to convert the raw data into something readable?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 14:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74637#M18818</guid>
      <dc:creator>cgkades</dc:creator>
      <dc:date>2012-09-28T14:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Convert audit.log TTY data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74638#M18819</link>
      <description>&lt;P&gt;Can you provide an example of what you see and what you want to see? Are you looking for something like &lt;A href="http://splunk-base.splunk.com/answers/60048/how-to-include-completely-missing-fields-in-results"&gt;this&lt;/A&gt; where you would convert the data within a field? Or are you not getting fields, and wnat to extract them into a fields?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 16:33:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74638#M18819</guid>
      <dc:creator>jsb22</dc:creator>
      <dc:date>2012-09-28T16:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Convert audit.log TTY data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74639#M18820</link>
      <description>&lt;P&gt;I would like to translate the data=[hex string].&lt;BR /&gt;
the entry in splunk:&lt;/P&gt;

&lt;P&gt;type=TTY msg=audit(1234123.123:6644): tty pid=12345 uid=0 auid=1234 major=137 minor=20 comm="bash" data=121212F0D00DDD0121212423400D host=myhostname | sourcetype=linux_audit | source=/var/log/audit/audit.log&lt;/P&gt;

&lt;P&gt;all numbers except uid=0 were replaced with random numbers, as well as the host name.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 18:10:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74639#M18820</guid>
      <dc:creator>cgkades</dc:creator>
      <dc:date>2012-09-28T18:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: Convert audit.log TTY data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74640#M18821</link>
      <description>&lt;P&gt;It looks like it's a hex string that is just ascii data. I was able to convert the data manually in python. Can anyone point me in the direction of the docs that cover how to run a script against a certain field? I only want it to translate the field "data=" from hex to ascii when the type=TTY&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 18:35:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74640#M18821</guid>
      <dc:creator>cgkades</dc:creator>
      <dc:date>2012-09-28T18:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: Convert audit.log TTY data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74641#M18822</link>
      <description>&lt;P&gt;Running into the same issue, can help mention how to tried to extract field "data" into string format.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 07:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74641#M18822</guid>
      <dc:creator>dharshini</dc:creator>
      <dc:date>2019-01-24T07:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Convert audit.log TTY data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74642#M18823</link>
      <description>&lt;P&gt;try this:&lt;/P&gt;

&lt;P&gt;Example raw log:&lt;BR /&gt;
type=USER_TTY msg=audit(1573643958.798:1973): pid=2964 uid=0 auid=1000 ses=22 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 data=636174202F7661722F6C6F672F61756469742F61756469742E6C6F67207C206772657020555345525F545459UID="root" AUID="rdevega"&lt;/P&gt;

&lt;P&gt;splunk code:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your search here
| eval keystrokes = urldecode(replace(data,"([0-9A-F]{2})","%\1"))
| table data keystrokes
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;results:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/275134-anotacion-2019-11-13-122243.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:57:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-audit-log-TTY-data/m-p/74642#M18823</guid>
      <dc:creator>rafadvega</dc:creator>
      <dc:date>2020-09-30T02:57:18Z</dc:date>
    </item>
  </channel>
</rss>

