<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Citrix get-brokersession in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/692491#M235701</link>
    <description>&lt;P&gt;I have a powershell script running get-brokersession which then exports the results to a txt file.&amp;nbsp; &amp;nbsp;The file is then forwarded via the Universal Forwarder.&amp;nbsp; &amp;nbsp; &amp;nbsp;Trying to create a search that bases the output data via the session key.&amp;nbsp; &amp;nbsp;The Citrix add-on app is not allowed at our location.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2024 14:37:03 GMT</pubDate>
    <dc:creator>kmm2</dc:creator>
    <dc:date>2024-07-05T14:37:03Z</dc:date>
    <item>
      <title>Splunk Citrix get-brokersession</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/692491#M235701</link>
      <description>&lt;P&gt;I have a powershell script running get-brokersession which then exports the results to a txt file.&amp;nbsp; &amp;nbsp;The file is then forwarded via the Universal Forwarder.&amp;nbsp; &amp;nbsp; &amp;nbsp;Trying to create a search that bases the output data via the session key.&amp;nbsp; &amp;nbsp;The Citrix add-on app is not allowed at our location.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 14:37:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/692491#M235701</guid>
      <dc:creator>kmm2</dc:creator>
      <dc:date>2024-07-05T14:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Citrix get-brokersession</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/692520#M235708</link>
      <description>&lt;P&gt;To post an answerable question in this forum, it is important to illustrate your input, e.g., raw events (anonymize as needed), illustrate/mock desired output, then explain the logic between illustrated input and desired output including any relevant available fields, data characteristics, etc.&lt;/P&gt;&lt;P&gt;From your description, all volunteers here get is that you have some file ingested via Universal Forwarder and your data contains some sort of session key.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 20:54:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/692520#M235708</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-07-05T20:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Citrix get-brokersession</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/692534#M235711</link>
      <description>&lt;P&gt;And your actual problem with this is...?&lt;/P&gt;&lt;P&gt;So far you told us what you're trying to do. OK, that's a sound approach if you can't use an app apparently containing some sort of scripted/modular input, you're spawning an external script preparing the data that you later ingest with monitor input from an intermediate file. Great.&lt;/P&gt;&lt;P&gt;Now how are we supposed to know what is in your data? And what is the desired result of your search?&lt;/P&gt;&lt;P&gt;Maybe for some very very common types of data (like standard windows event logs) one could expect a farily common knowledge about them but even then it's better to explicitly state your problem.&lt;/P&gt;&lt;P&gt;So - what _is_ your problem?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jul 2024 09:35:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/692534#M235711</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-06T09:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Citrix get-brokersession</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/692676#M235745</link>
      <description>&lt;P&gt;Thanks for the reply&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 19:13:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/692676#M235745</guid>
      <dc:creator>kmm2</dc:creator>
      <dc:date>2024-07-08T19:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Citrix get-brokersession</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/693797#M236018</link>
      <description>&lt;P&gt;When we run&amp;nbsp; get-brokersession&amp;nbsp; we have a txt file with time stamps in the txt file for events.&amp;nbsp; We can not get the date and time to show up in splunk.&amp;nbsp; We can get date only or time only.&amp;nbsp; &amp;nbsp;When we try to do both, the parsed data stops at a line where a&amp;nbsp; timestamp is located with no output.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 19:26:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/693797#M236018</guid>
      <dc:creator>kmm2</dc:creator>
      <dc:date>2024-07-18T19:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Citrix get-brokersession</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/693806#M236023</link>
      <description>&lt;P&gt;If you forwarder is not forwarding the complete file, there might be a problem with linebreaker. &amp;nbsp;This has nothing to do with how to search. &amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/bd-p/getting-data-in" target="_blank"&gt;Getting Data In&lt;/A&gt;&amp;nbsp;is a better forum.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 23:53:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/693806#M236023</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-07-18T23:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Citrix get-brokersession</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/693875#M236040</link>
      <description>&lt;P&gt;The forwarder is forwarding.&amp;nbsp; The information is broken up in splunk every time it comes across a line with a timestamp.&amp;nbsp; &amp;nbsp;Then a new field is created after the timestamp line until it hits another timestamp in the txt&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 16:53:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/693875#M236040</guid>
      <dc:creator>kmm2</dc:creator>
      <dc:date>2024-07-19T16:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Citrix get-brokersession</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/693896#M236046</link>
      <description>&lt;P&gt;Let's get back to basics: When your events are broken, using search technique to cope is the last thing to consider.&lt;/P&gt;&lt;P&gt;Can you post sample raw file, the exact event contents Splunk receives, and your properties.conf stanza corresponding to this sourcetype? &amp;nbsp;Without data, volunteers have nothing to go on.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jul 2024 16:56:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/693896#M236046</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-07-20T16:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Citrix get-brokersession</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/695576#M236511</link>
      <description>&lt;P&gt;Trying to update the props/transform.conf so that I can created fields for the items listed on the left side of the image below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FIELD_DELIMITER=:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;FIELD_NAMES=myfield1,myfield2,myfield3,myfield4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is what I am working with and have not had success&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kmm2_0-1723042604402.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32098iADA352714267EA3B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kmm2_0-1723042604402.png" alt="kmm2_0-1723042604402.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 14:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Citrix-get-brokersession/m-p/695576#M236511</guid>
      <dc:creator>kmm2</dc:creator>
      <dc:date>2024-08-07T14:59:52Z</dc:date>
    </item>
  </channel>
</rss>

