<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: need way to find this string in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632870#M219830</link>
    <description>&lt;P&gt;thank you for inputs but when trying to apply on whole log its fails&lt;BR /&gt;&lt;BR /&gt;Retrieve |5|act=Retrieve password suser=abcd fname=Root\Operating Systems-admin dvc= shost=1.1.1.1 dhost=asdfek duser=sasassa externalId= app= reason= cs1Label="Affected User Name" cs1= cs2Label="Safe Name" cs2=asasas cs3Label="Device Type" cs3=Operating System cs4Label="Database" cs4= cs5Label="Other info" cs5= cn1Label="Request Id" cn1= cn2Label="Ticket Id" cn2=CPM msg=CPM&amp;lt;5&amp;gt;138:13Z PRO-ASA CEF:0|Cyber-Ark|baba|11.2.0000|22|sas Verify wd|5|act=abs Verify pas&amp;nbsp; suser=SEFPEOJFEFL fname=Root\Operating System-SASASdfdfd= shost=1.1.1.1 dhost= duser=awsas externalId= app= reason= cs1Label="Affected User Name" cs1= cs2Label="Safe Name" cs2=test1 cs3Label="Device Type" cs3=Operating System cs4Label="Database" cs4= cs5Label="Other info" cs5= cn1Label="Request Id" cn1= cn2Label="Ticket Id" cn2=Ver msg=VerificationPeriodCEF:0|Cyber-Ark|&lt;STRONG&gt;abcdxyz|11.2.0000|64|14555|65|4774|13|32|8207|18|58|336|446|210812&amp;lt;&lt;/STRONG&gt;5&amp;gt;1 2023-02-28T23:38:15Z PRO-asa CEF:0|Cyber-Ark|Vault|11.2.0000|51|Retrieve File|5|act=Retrieve File suser=abcd fname=Root\Policies\Policy-GenericWebApp.ini dvc= shost=1.1.1.1 dhost= duser= externalId= app= reason= cs1Label="Affected User Name" cs1= cs2Label="Safe Name" cs2=CMDsas cs3Label="Device Type" cs3= cs4Label="sasasas"&lt;/P&gt;</description>
    <pubDate>Wed, 01 Mar 2023 21:26:27 GMT</pubDate>
    <dc:creator>ajit4242</dc:creator>
    <dc:date>2023-03-01T21:26:27Z</dc:date>
    <item>
      <title>How do I find this string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632830#M219821</link>
      <description>&lt;P&gt;my string is&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;"abcdxyz&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;11.2.0000&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;56&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;12120&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;32&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;1005&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;15&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;32&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;7742&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;5&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;54&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;336&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;446&lt;/SPAN&gt;&lt;SPAN&gt;|&lt;/SPAN&gt;&lt;SPAN class=""&gt;203473&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;above string is string in huge log entry , I want to extract above string and then last 4 fields and from above string to map for graph.&lt;BR /&gt;&lt;BR /&gt;I tried using&amp;nbsp; &amp;nbsp;(name="*&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;abcdxyz&lt;/SPAN&gt;&lt;/SPAN&gt;|11.2.0000|[0-9]|[0-9]|[0-9]|[0-9]|[0-9]|[0-9]|[0-9]|[0-9]|[0-9]|[0-9]|[0-9]|[0-9]&amp;lt;*")&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;but getting a lot of noise there&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 15:19:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632830#M219821</guid>
      <dc:creator>ajit4242</dc:creator>
      <dc:date>2023-03-02T15:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: need way to find this string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632845#M219823</link>
      <description>&lt;LI-CODE lang="markup"&gt;| eval name=split(name,"|")
| eval lastfour=mvindex(name,-4,-1)&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 01 Mar 2023 18:25:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632845#M219823</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-01T18:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: need way to find this string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632870#M219830</link>
      <description>&lt;P&gt;thank you for inputs but when trying to apply on whole log its fails&lt;BR /&gt;&lt;BR /&gt;Retrieve |5|act=Retrieve password suser=abcd fname=Root\Operating Systems-admin dvc= shost=1.1.1.1 dhost=asdfek duser=sasassa externalId= app= reason= cs1Label="Affected User Name" cs1= cs2Label="Safe Name" cs2=asasas cs3Label="Device Type" cs3=Operating System cs4Label="Database" cs4= cs5Label="Other info" cs5= cn1Label="Request Id" cn1= cn2Label="Ticket Id" cn2=CPM msg=CPM&amp;lt;5&amp;gt;138:13Z PRO-ASA CEF:0|Cyber-Ark|baba|11.2.0000|22|sas Verify wd|5|act=abs Verify pas&amp;nbsp; suser=SEFPEOJFEFL fname=Root\Operating System-SASASdfdfd= shost=1.1.1.1 dhost= duser=awsas externalId= app= reason= cs1Label="Affected User Name" cs1= cs2Label="Safe Name" cs2=test1 cs3Label="Device Type" cs3=Operating System cs4Label="Database" cs4= cs5Label="Other info" cs5= cn1Label="Request Id" cn1= cn2Label="Ticket Id" cn2=Ver msg=VerificationPeriodCEF:0|Cyber-Ark|&lt;STRONG&gt;abcdxyz|11.2.0000|64|14555|65|4774|13|32|8207|18|58|336|446|210812&amp;lt;&lt;/STRONG&gt;5&amp;gt;1 2023-02-28T23:38:15Z PRO-asa CEF:0|Cyber-Ark|Vault|11.2.0000|51|Retrieve File|5|act=Retrieve File suser=abcd fname=Root\Policies\Policy-GenericWebApp.ini dvc= shost=1.1.1.1 dhost= duser= externalId= app= reason= cs1Label="Affected User Name" cs1= cs2Label="Safe Name" cs2=CMDsas cs3Label="Device Type" cs3= cs4Label="sasasas"&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 21:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632870#M219830</guid>
      <dc:creator>ajit4242</dc:creator>
      <dc:date>2023-03-01T21:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: need way to find this string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632883#M219834</link>
      <description>&lt;P&gt;Has the field (msg?) already been extracted?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 22:06:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632883#M219834</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-01T22:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: need way to find this string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632959#M219876</link>
      <description>&lt;P&gt;no, its just the raw log&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 10:35:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632959#M219876</guid>
      <dc:creator>ajit4242</dc:creator>
      <dc:date>2023-03-02T10:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: need way to find this string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632966#M219879</link>
      <description>&lt;P&gt;Given you earlier attempt, perhaps you could try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "abcdxyz\|11\.2\.0000\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|(?&amp;lt;lastfour&amp;gt;[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\&amp;lt;)"&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 02 Mar 2023 11:14:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632966#M219879</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-02T11:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: need way to find this string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632968#M219880</link>
      <description>&lt;P&gt;OK. I'm not sure if it's the case of you pasting the log into the webpage or is it the original data but it seems that it's not properly broken into separate events. That's one thing which must be properly done before you can reliably work with those logs.&lt;/P&gt;&lt;P&gt;Secondly, CyberArk produces CEF logs for which there are several Add-Ons (you might want to compile your own from them; I'm not sure if there is an official Splunk-supplied Add-on for CEF).&lt;/P&gt;&lt;P&gt;Thirdly, this CEF seems a bit misformatted.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 11:17:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/632968#M219880</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-03-02T11:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: need way to find this string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/633047#M219902</link>
      <description>&lt;P&gt;was able to get it working, first I just got it for all values and then filtered it, thank you for your help&lt;BR /&gt;&lt;BR /&gt;VaultMonitor\|[0-9]+\.[0-9]+\.[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+\|[0-9]+&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 18:52:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-find-this-string/m-p/633047#M219902</guid>
      <dc:creator>ajit4242</dc:creator>
      <dc:date>2023-03-02T18:52:22Z</dc:date>
    </item>
  </channel>
</rss>

