<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I need help with my props conf to extract fields correctly. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/I-need-help-with-my-props-conf-to-extract-fields-correctly/m-p/567153#M197639</link>
    <description>&lt;P&gt;What is the extra information that is extracted.&lt;/P&gt;&lt;P&gt;The \ in EXTRACT-Result is not needed.&lt;/P&gt;&lt;P&gt;Consider using &lt;FONT face="courier new,courier"&gt;\w+&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;\S+&lt;/FONT&gt;&amp;nbsp;instead of &lt;FONT face="courier new,courier"&gt;.+&lt;/FONT&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Sep 2021 19:26:55 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-09-15T19:26:55Z</dc:date>
    <item>
      <title>I need help with my props conf to extract fields correctly.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-need-help-with-my-props-conf-to-extract-fields-correctly/m-p/567133#M197635</link>
      <description>&lt;P&gt;When I test the regex in both regex101 and using the rex command in the search bar and they parsed out the fields correctly. Now that i have added them to the props conf on the search head, they are capturing extra information.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Result field is the one that is mainly caputuring the SessionID which the the capture is Verified or Failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all for your help with this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;props.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[exp_test]&lt;BR /&gt;DATETIME_CONFIG =&lt;BR /&gt;LINE_BREAKER = ([\r\n]+)&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;category = Custom&lt;BR /&gt;pulldown_type = true&lt;BR /&gt;CHECK_FOR_HEADER = false&lt;BR /&gt;CHARSET = AUTO&lt;/P&gt;&lt;P&gt;EXTRACT-SessionID = (?&amp;lt;=SessionID:)(?P&amp;lt;SessionID&amp;gt;.+)&lt;BR /&gt;EXTRACT-Result = \VerificationResult:(?P&amp;lt;Result&amp;gt;.+)&lt;BR /&gt;EXTRACT-UserName = (?&amp;lt;=User:)(?P&amp;lt;UserName&amp;gt;.+)&lt;BR /&gt;EXTRACT-Response_1 = (?&amp;lt;=Response_1:)(?P&amp;lt;Response_1&amp;gt;.+)&lt;BR /&gt;EXTRACT-Response_2 = (?&amp;lt;=Response_2:)(?P&amp;lt;Response_1&amp;gt;.+)&lt;/P&gt;&lt;P&gt;Sample Log&lt;/P&gt;&lt;P&gt;Time: 13-09-2021 10:08:19&lt;BR /&gt;VerificationResult: Failed&lt;BR /&gt;SessionID: K3K2N2G3JPSOZNOWJFOMFPBP.pidd1v-210913090809460797217&lt;BR /&gt;User: LAST, FIRST&lt;BR /&gt;13-09-2021 10:10:18 Response_1: 1st reqest Sent! for User: LAST, FIRST&lt;BR /&gt;13-09-2021 10:10:19 Response_1: 1st response received! for User: LAST, FIRST&lt;BR /&gt;Time: 13-09-2021 10:10:19&lt;BR /&gt;SessionID and User Mapping:&lt;BR /&gt;SessionID: 3EV6PLCHK795Z8FQBKKYS3Z3.pidd2v-210913091018537820706&lt;BR /&gt;User: LAST, FIRST&lt;BR /&gt;13-09-2021 10:15:13 Response_1: 1st reqest Sent! for User: LAST, FIRST&lt;BR /&gt;13-09-2021 10:15:14 Response_1: 1st response received! for User: LAST, FIRST&lt;BR /&gt;Time: 13-09-2021 10:15:14&lt;BR /&gt;SessionID and User Mapping:&lt;BR /&gt;SessionID: GAWJ1C7ZWNAWCVTEEIWGE3LL.pidd2v-210913091513558630064&lt;BR /&gt;User: LAST, FIRST&lt;BR /&gt;13-09-2021 10:15:33 Response_1: 1st reqest Sent! for User: LAST, FIRST&lt;BR /&gt;13-09-2021 10:15:33 Response_1: 1st response received! for User: LAST, FIRST&lt;BR /&gt;13-09-2021 10:15:38 Response_1: 1st reqest Sent! for User: LAST, FIRST&lt;BR /&gt;13-09-2021 10:15:39 Response_1: 1st response received! for User: LAST, FIRST&lt;BR /&gt;Time: 13-09-2021 10:15:39&lt;BR /&gt;SessionID and User Mapping:&lt;BR /&gt;SessionID: 2SYZV3QHCZKYM2YTYIJLVL3E.pidd2v-210913091538460803649&lt;BR /&gt;User: LAST, FIRST&lt;BR /&gt;13-09-2021 10:15:47 Response_1: 2nd request sent! for the user verification SessionID: 2SYZV3QHCZKYM2YTYIJLVL3E.pidd2v-210913091538460803649&lt;BR /&gt;13-09-2021 10:15:48 Response_1: 2nd response received! for user verification SessionID: 2SYZV3QHCZKYM2YTYIJLVL3E.pidd2v-210913091538460803649&lt;BR /&gt;Time: 13-09-2021 10:15:48&lt;BR /&gt;VerificationResult: Verified&lt;BR /&gt;SessionID: 2SYZV3QHCZKYM2YTYIJLVL3E.pidd2v-210913091538460803649&lt;BR /&gt;User: LAST, FIRST&lt;BR /&gt;13-09-2021 10:16:47 Response_1: 1st reqest Sent! for User: LAST, FIRST&lt;BR /&gt;13-09-2021 10:16:48 Response_1: 1st response received! for User: LAST, FIRST&lt;BR /&gt;Time: 13-09-2021 10:16:48&lt;BR /&gt;SessionID and User Mapping:&lt;BR /&gt;SessionID: D5JVVUR3AAKFURITHCI993H9.pidd2v-210913091647448944771&lt;BR /&gt;User: LAST, FIRST&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 15:53:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-need-help-with-my-props-conf-to-extract-fields-correctly/m-p/567133#M197635</guid>
      <dc:creator>djreschke</dc:creator>
      <dc:date>2021-09-15T15:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: I need help with my props conf to extract fields correctly.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/I-need-help-with-my-props-conf-to-extract-fields-correctly/m-p/567153#M197639</link>
      <description>&lt;P&gt;What is the extra information that is extracted.&lt;/P&gt;&lt;P&gt;The \ in EXTRACT-Result is not needed.&lt;/P&gt;&lt;P&gt;Consider using &lt;FONT face="courier new,courier"&gt;\w+&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;\S+&lt;/FONT&gt;&amp;nbsp;instead of &lt;FONT face="courier new,courier"&gt;.+&lt;/FONT&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 19:26:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/I-need-help-with-my-props-conf-to-extract-fields-correctly/m-p/567153#M197639</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-15T19:26:55Z</dc:date>
    </item>
  </channel>
</rss>

