<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: collect Aruba SNMP and quotes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696531#M236720</link>
    <description>&lt;P&gt;That's because you're collecting the contents of the event in a field called logEvent. If you want to collect this as raw event, you obviously have to set the _raw field.&lt;/P&gt;&lt;P&gt;You are aware that using other sourcetype than stash (or stash_hec for output_format=hec) uses up your license?&lt;/P&gt;&lt;P&gt;You can also have issues with timestamps if you don't set _time properly before collecting (and generally you should set all default metadata fields)&lt;/P&gt;</description>
    <pubDate>Fri, 16 Aug 2024 18:54:49 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-08-16T18:54:49Z</dc:date>
    <item>
      <title>collect Aruba SNMP and quotes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696529#M236719</link>
      <description>&lt;P&gt;I want to manually add an event to an index, using collect seems to be the most straight forward method. I am asking for a method to use makeresults and eval to add field quotes like the native Aruba SNMP log format to send in raw format to an index&lt;/P&gt;
&lt;P&gt;Background: We had a power outage at one of our sites. Report and Alert searches look for active user Wi-Fi sessions. Because&amp;nbsp;the access points were offline, when users left for the day the Wi-Fi session end log events were not sent from Aruba to Splunk&amp;nbsp;, which is causing false positive alerts.&lt;/P&gt;
&lt;P&gt;The Aruba SNMP logs look like this:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;timestamp=1723828026&lt;/SPAN&gt; &lt;SPAN class=""&gt;notification_from_address&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;172.20.0.69&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;notification_from_port&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;34327&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::mib-2.1.3.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;10679000&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::snmpModules.1.1.4.1.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;1.3.6.1.4.1.14823.2.3.1.11.1.2.1219&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.60&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;0x07e808100a0706002d0700&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.51.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;192.168.50.54&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.52.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;0xd8be1f2f9c1a&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.3.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;0x2462ce8053b1&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.94.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;RAP1053a&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.28.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.59.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.103.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.136.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;11&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.137.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My search:&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;| makeresults
| eval timeStamp=now()
| eval logEvent="timestamp=1723830464 notification_from_address = \"172.20.0.17\" notification_from_port = \"43015\" SNMPv2-SMI::mib-2.1.3.0 = \"2063900\" SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.60 = \"0x07e8080e0d310f002d0700\" SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.51.0 = \"192.168.50.67\" SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.52.0 = \"0xd8be1f7d1076\" SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.3.0 = \"0x482f6b06b171\" SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.94.0 = \"AP7\" SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.28.0 = \"0\" SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.59.0 = \"0\" SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.103.0 = \"2\" SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.136.0 = \"10\" SNMPv2-SMI::enterprises.14823.2.3.1.11.1.1.137.0 = \"1\""

| collect index=aruba_snmp sourcetype=snmp_traps output_format=raw testmode=true

&lt;/LI-CODE&gt;
&lt;P&gt;The search result looks like what I want but when sent in raw format the escape \ are visible. How do I obscure or remove the \ in raw format? Thank you for any help in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 21:09:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696529#M236719</guid>
      <dc:creator>Seawheels51</dc:creator>
      <dc:date>2024-08-16T21:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: collect Aruba SNMP and quotes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696531#M236720</link>
      <description>&lt;P&gt;That's because you're collecting the contents of the event in a field called logEvent. If you want to collect this as raw event, you obviously have to set the _raw field.&lt;/P&gt;&lt;P&gt;You are aware that using other sourcetype than stash (or stash_hec for output_format=hec) uses up your license?&lt;/P&gt;&lt;P&gt;You can also have issues with timestamps if you don't set _time properly before collecting (and generally you should set all default metadata fields)&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 18:54:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696531#M236720</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-16T18:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: collect Aruba SNMP and quotes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696725#M236787</link>
      <description>&lt;P&gt;I was not aware of the licensing implications, thank you and I'll stay in compliance.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 14:47:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696725#M236787</guid>
      <dc:creator>Seawheels51</dc:creator>
      <dc:date>2024-08-19T14:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: collect Aruba SNMP and quotes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696730#M236790</link>
      <description>&lt;P&gt;I mean you use up additional license amount for indexing additional data using the collect command unless you use the stash or stash_hec sourcetypes. So each events you firstly index into index A and then search, transform and collect into index B will cost you twice (roughly - depending on what you do with it in terms of processing before collecting) the license usage that it uses just be indexing it into index A. Whether you're within your license limits or not depends of course on the overall amount of ingested data and your license size.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 15:01:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696730#M236790</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-19T15:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: collect Aruba SNMP and quotes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696736#M236793</link>
      <description>&lt;P&gt;Appreciate the clarification, I have 30%+ headroom with my license so a couple of onetime events should not be an issue.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 15:21:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696736#M236793</guid>
      <dc:creator>Seawheels51</dc:creator>
      <dc:date>2024-08-19T15:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: collect Aruba SNMP and quotes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696738#M236794</link>
      <description>&lt;P&gt;I have the collect search working, eval _raw="field1","field2", ...&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SCS/current/SearchReference/ConversionFunctions" target="_blank"&gt;Conversion functions - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thank you for pointing me in the right direction and well done &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 15:42:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/collect-Aruba-SNMP-and-quotes/m-p/696738#M236794</guid>
      <dc:creator>Seawheels51</dc:creator>
      <dc:date>2024-08-19T15:42:08Z</dc:date>
    </item>
  </channel>
</rss>

