<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Troubleshooting a multi-line, multi-value field extraction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Troubleshooting-a-multi-line-multi-value-field-extraction/m-p/155951#M43879</link>
    <description>&lt;P&gt;Markdown is playing up:&lt;BR /&gt;
klzzwxh:0124 (etc.) should be underscore.  Too frustrated to try and fix it!&lt;/P&gt;</description>
    <pubDate>Fri, 15 Aug 2014 11:01:06 GMT</pubDate>
    <dc:creator>skooby</dc:creator>
    <dc:date>2014-08-15T11:01:06Z</dc:date>
    <item>
      <title>Troubleshooting a multi-line, multi-value field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Troubleshooting-a-multi-line-multi-value-field-extraction/m-p/155947#M43875</link>
      <description>&lt;P&gt;My event is mostly output from java's keytool utility, and looks like this......&lt;BR /&gt;
  (except for the top line which is output by a wrapper script)&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;BR /&gt;
CellDefaultTrustStore - /opt/IBM/WebSphere/AppServer/profiles/dmgr/config/cells/mycell/trust.p12&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Keystore type: PKCS12&lt;BR /&gt;
Keystore provider: IBMJCE&lt;/P&gt;

&lt;P&gt;Your keystore contains 4 entries&lt;/P&gt;

&lt;P&gt;Alias name: datapower&lt;BR /&gt;
Creation date: 01-Jan-1970&lt;BR /&gt;
Entry type: trustedCertEntry&lt;/P&gt;

&lt;P&gt;Owner: OU=Root CA, O="DataPower Technology, Inc.", C=US&lt;BR /&gt;
Issuer: OU=Root CA, O="DataPower Technology, Inc.", C=US&lt;BR /&gt;
Serial number: 0&lt;BR /&gt;
Valid from: 11/06/03 19:23 until: 06/06/23 19:23&lt;BR /&gt;
Certificate fingerprints:&lt;BR /&gt;
           MD5:  AB:CD:EF:01:23:45:67:89:AB:CD:EF:01:23:45:67:89&lt;BR /&gt;
           SHA1: AB:CD:EF:01:23:45:67:89:AB:CD:EF:01:23:45:67:89:AB:CD:EF:01&lt;/P&gt;

&lt;P&gt;*******************************************&lt;BR /&gt;
*******************************************&lt;/P&gt;

&lt;P&gt;Alias name: root&lt;BR /&gt;
Creation date: 01-Jan-1970&lt;BR /&gt;
Entry type: trustedCertEntry&lt;/P&gt;

&lt;P&gt;Owner: CN=server.acme.co.uk, OU=Root Certificate, OU=mycell, OU=dmgrnode, O=IBM, C=US&lt;BR /&gt;
Issuer: CN=server.acme.co.uk, OU=Root Certificate, OU=mycell, OU=dmgrnode, O=IBM, C=US&lt;BR /&gt;
Serial number: 1234567890abcdef&lt;BR /&gt;
Valid from: 14/07/11 15:00 until: 10/07/26 15:00&lt;BR /&gt;
Certificate fingerprints:&lt;BR /&gt;
           MD5:  CD:EF:01:23:45:67:89:AB:CD:EF:01:23:45:67:89:AB&lt;BR /&gt;
           SHA1: CD:EF:01:23:45:67:89:AB:CD:EF:01:23:45:67:89:AB:CD:EF:01:23&lt;/P&gt;

&lt;P&gt;*******************************************&lt;BR /&gt;
*******************************************&lt;/P&gt;

&lt;P&gt;Alias name: default&lt;BR /&gt;
Creation date: 01-Jan-1970&lt;BR /&gt;
Entry type: trustedCertEntry&lt;/P&gt;

&lt;P&gt;Owner: CN=server.acme.co.uk, OU=mycell, OU=dmgrnode, O=IBM, C=US&lt;BR /&gt;
Issuer: CN=server.acme.co.uk, OU=Root Certificate, OU=mycell, OU=dmgrnode, O=IBM, C=US&lt;BR /&gt;
Serial number: f1234567890abcde&lt;BR /&gt;
Valid from: 23/03/13 21:30 until: 23/03/14 21:30&lt;BR /&gt;
Certificate fingerprints:&lt;BR /&gt;
           MD5:  EF:01:23:45:67:89:AB:CD:EF:01:23:45:67:89:AB:CD&lt;BR /&gt;
           SHA1: EF:01:23:45:67:89:AB:CD:EF:01:23:45:67:89:AB:CD:EF:01:23:CD&lt;/P&gt;

&lt;P&gt;*******************************************&lt;BR /&gt;
*******************************************&lt;/P&gt;

&lt;P&gt;Alias name: default_1&lt;BR /&gt;
Creation date: 01-Jan-1970&lt;BR /&gt;
Entry type: trustedCertEntry&lt;/P&gt;

&lt;P&gt;Owner: CN=server.acme.co.uk, OU=mycell, OU=dmgrnode, O=IBM, C=US&lt;BR /&gt;
Issuer: CN=server.acme.co.uk, OU=Root Certificate, OU=mycell, OU=dmgrnode, O=IBM, C=US&lt;BR /&gt;
Serial number: ef1234567890abcd&lt;BR /&gt;
Valid from: 14/06/14 21:30 until: 14/06/15 21:30&lt;BR /&gt;
Certificate fingerprints:&lt;BR /&gt;
           MD5:  01:23:45:67:89:AB:CD:EF:01:23:45:67:89:AB:CD:EF&lt;BR /&gt;
           SHA1: 01:23:45:67:89:AB:CD:EF:01:23:45:67:89:AB:CD:EF:01:23:CD:EF&lt;/P&gt;

&lt;P&gt;*******************************************&lt;BR /&gt;
*******************************************&lt;BR /&gt;
&lt;/P&gt;

&lt;P&gt;From this, I want to generate a report or table that looks something like this:&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
KeyStoreName   KeyStoreLocation                    KeyAlias   KeySerial         KeyExpiry&lt;BR /&gt;
CellDefaultTrustStore /opt/IBM/WebSphere/AppServer/profiles/dmgr/config/cells/mycell/trust.p12  datapower  0                 06/06/23 19:23&lt;BR /&gt;
CellDefaultTrustStore /opt/IBM/WebSphere/AppServer/profiles/dmgr/config/cells/mycell/trust.p12  root       1234567890abcdef  10/07/26 15:00&lt;BR /&gt;
CellDefaultTrustStore /opt/IBM/WebSphere/AppServer/profiles/dmgr/config/cells/mycell/trust.p12  default    f1234567890abcde  23/03/14 21:30&lt;BR /&gt;
CellDefaultTrustStore /opt/IBM/WebSphere/AppServer/profiles/dmgr/config/cells/mycell/trust.p12  default_1  ef1234567890abcd  14/06/15 21:30&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I have tried two approaches:&lt;/P&gt;

&lt;P&gt;(1) this one - &lt;A href="http://answers.splunk.com/answers/112311/multi-value-field-extraction"&gt;multi-value-field-extraction&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;with this one I have only tried to get the KeyAlias&lt;/P&gt;

&lt;P&gt;props.conf:&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
[middleware_unix_cert_scanner1]&lt;BR /&gt;
DATETIME_CONFIG = CURRENT&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
LINE_BREAKER = (=========================================================================)&lt;BR /&gt;
TRUNCATE = 100000&lt;BR /&gt;
TRANSFORMS-temp-field = temp-field&lt;BR /&gt;
TRANSFORMS-WASKeyStoreEntryAlias = WASKeyStoreEntryAlias&lt;BR /&gt;
&lt;/CODE&gt;  &lt;/P&gt;

&lt;P&gt;transforms.conf:&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
[temp-field]&lt;BR /&gt;
REGEX=Alias name: (.*)&lt;BR /&gt;
FORMAT=temporary_field::$1&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;[WASKeyStoreEntryAlias]&lt;BR /&gt;
SOURCE_KEY=temporary_field&lt;BR /&gt;
REGEX=([a-z_+)&lt;BR /&gt;
FORMAT=WASKeyStoreEntryAlias::$1&lt;BR /&gt;
MV_ADD=true&lt;BR /&gt;
  &lt;/P&gt;

&lt;P&gt;(here I used WASKeyStoreEntryAlias as the field name rather than the shorter KeyAlias)&lt;/P&gt;

&lt;P&gt;The top 4 lines in the props.conf stanza are to break the script output into events - these work as desired to create the event I have pasted above.&lt;/P&gt;

&lt;P&gt;(2) this one - &lt;A href="http://answers.splunk.com/answers/41803/multi-line-multi-value-key-extraction-issue"&gt;multi-line-multi-value-key-extraction-issue&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I should probably shoot for this one as I do need to get multiple multi-valued fields.....  but can't get anywhere with this, either:&lt;/P&gt;

&lt;P&gt;props.conf:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;BR /&gt;
[middleware_unix_cert_scanner1]&lt;BR /&gt;
DATETIME_CONFIG = CURRENT&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
LINE_BREAKER = (=========================================================================)&lt;BR /&gt;
TRUNCATE = 100000&lt;BR /&gt;
REPORT-my_report = report_mv&lt;BR /&gt;
&lt;/CODE&gt;  &lt;/P&gt;

&lt;P&gt;transforms.conf:&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
[report_mv]&lt;BR /&gt;
REGEX=Alias name: (\w+)&lt;BR /&gt;
FORMAT=WASKeyStoreEntryAlias::$1&lt;BR /&gt;
MV_ADD=true&lt;BR /&gt;
&lt;/CODE&gt;  &lt;/P&gt;

&lt;P&gt;(again, used WASKeyStoreEntryAlias as the field name rather than the shorter KeyAlias)&lt;/P&gt;

&lt;P&gt;I thought this meant WASKeyStoreEntryAlias would be defined and I could do a search like:&lt;/P&gt;

&lt;P&gt;sourcetype="middleware_unix_cert_scanner1" | table _time WASKeyStoreEntryAlias&lt;/P&gt;

&lt;P&gt;and it would come up with some values for WASKeyStoreEntryAlias - but when I do this, the WASKeyStoreEntryAlias column is blank.&lt;/P&gt;

&lt;P&gt;A few side questions which may help my understanding:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;how do I retrieve the value of the multi-valued field?  at the moment I am unable to confirm even if the regex works..&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;how can I confirm my transforms.conf is being read/processed?  I have a history of putting the files in the wrong places!  it's in the same app as props.conf but inputs.conf is in a different app under deployment-apps, not apps.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;does it need the event to occur in order to parse it per the transforms.conf?  the script only runs every 24h and hasn't run since I attempted option (2)&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 24 Jul 2014 09:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Troubleshooting-a-multi-line-multi-value-field-extraction/m-p/155947#M43875</guid>
      <dc:creator>skooby</dc:creator>
      <dc:date>2014-07-24T09:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a multi-line, multi-value field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Troubleshooting-a-multi-line-multi-value-field-extraction/m-p/155948#M43876</link>
      <description>&lt;P&gt;Just noticed there's a typo in my regex for approach (1) (missing ]):&lt;/P&gt;

&lt;P&gt;REGEX=([a-z_+)&lt;/P&gt;

&lt;P&gt;However, approach (2) is probably the most appropriate for me so I'm not going to correct &amp;amp; retest (1) unless anyone has a compelling reason to.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2014 13:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Troubleshooting-a-multi-line-multi-value-field-extraction/m-p/155948#M43876</guid>
      <dc:creator>skooby</dc:creator>
      <dc:date>2014-07-24T13:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a multi-line, multi-value field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Troubleshooting-a-multi-line-multi-value-field-extraction/m-p/155949#M43877</link>
      <description>&lt;P&gt;Looking at&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/4075/whats-the-best-way-to-track-down-propsconf-problems"&gt;whats-the-best-way-to-track-down-propsconf-problems&lt;/A&gt;&lt;BR /&gt;
and mainly&lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings"&gt;Where_do_I_configure_my_Splunk_settings&lt;/A&gt;,&lt;/P&gt;

&lt;P&gt;I think I should have configured the REPORT* settings under my search app in deployment-apps, not under my parsing app in apps.&lt;/P&gt;

&lt;P&gt;Testing it now...&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2014 14:49:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Troubleshooting-a-multi-line-multi-value-field-extraction/m-p/155949#M43877</guid>
      <dc:creator>skooby</dc:creator>
      <dc:date>2014-07-24T14:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a multi-line, multi-value field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Troubleshooting-a-multi-line-multi-value-field-extraction/m-p/155950#M43878</link>
      <description>&lt;P&gt;In the end (thanks to my local Splunk guru) this was solved by:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;changing the scripted input so that the line&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;"CellDefaultTrustStore - /opt/IBM/WebSphere/AppServer/profiles/dmgr/config/cells/mycell/trust.p12"&lt;/P&gt;

&lt;P&gt;was output for each keystore stanza, and breaking on ++++++ (also added some extra text to make it easier to pattern match)&lt;/P&gt;

&lt;P&gt;This meant each event looked like this:&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
WASKeyStoreName: CellDefaultTrustStore&lt;BR /&gt;
WASKeyStoreLocation: /opt/IBM/WebSphere/AppServer/profiles/dmgr/config/cells/mycell/trust.p12&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Keystore type: PKCS12 &lt;BR /&gt;
Keystore provider: IBMJCE&lt;/P&gt;

&lt;P&gt;Alias name: datapower &lt;BR /&gt;
Creation date: 01-Jan-1970 &lt;BR /&gt;
Entry type: trustedCertEntry&lt;/P&gt;

&lt;P&gt;Owner: OU=Root CA, O="DataPower Technology, Inc.", C=US &lt;BR /&gt;
Issuer: OU=Root CA, O="DataPower Technology, Inc.", C=US &lt;BR /&gt;
Serial number: 0 &lt;BR /&gt;
Valid from: 11/06/03 19:23 until: 06/06/23 19:23 &lt;BR /&gt;
Certificate fingerprints:&lt;BR /&gt;
 MD5: AB:CD:EF:01:23:45:67:89:AB:CD:EF:01:23:45:67:89&lt;BR /&gt;
 SHA1: AB:CD:EF:01:23:45:67:89:AB:CD:EF:01:23:45:67:89:AB:CD:EF:01&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;&lt;/P&gt;

&lt;P&gt;Then (the exciting bit) we used mvzip and mvexpand...&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
sourcetype=this |&lt;BR /&gt;
rex "WASKeyStoreName:\s+(?P&lt;WAS&gt;.*)" | &lt;BR /&gt;
rex "WASKeyStoreLocation:\s+(?P&lt;WAS&gt;.*)" | &lt;BR /&gt;
rex "StoreType:\s+(?P&lt;STORETYPE&gt;.*)" |&lt;BR /&gt;
rex "Alias:\s+(?P&lt;ALIAS&gt;.*)" |&lt;BR /&gt;
rex "Alias name:\s+(?P&lt;ALIAS&gt;.*)" |&lt;BR /&gt;
rex "Creation date:\s+(?P&lt;CREATION&gt;.*)" |&lt;BR /&gt;
rex "Entry type:\s+(?P&lt;ENTRY&gt;.*)" |&lt;BR /&gt;
rex "Certificate chain length: (?P&lt;CERT&gt;\d+)" |&lt;BR /&gt;
rex max_match=0 "Certificate[(?P&lt;CERT&gt;\d+)]" |&lt;BR /&gt;
rex max_match=0 "Owner:\s+(?P&lt;OWNER&gt;.*)" |&lt;BR /&gt;
rex max_match=0 "Issuer:\s+(?P&lt;ISSUER&gt;.*)" |&lt;BR /&gt;
rex max_match=0 "Serial number:\s+(?P&lt;SERIAL&gt;.*)" |&lt;BR /&gt;
rex max_match=0 "Valid from:\s+(?P&lt;VALIDFROM&gt;.*)\s+until:(?P&lt;VALIDUNTIL&gt;.*)" |&lt;BR /&gt;
rex max_match=0 "\s+MD5:\s+(?P&lt;MD5&gt;.*)" |&lt;BR /&gt;
rex max_match=0 "\s+SHA1:\s+(?P&lt;SHA1&gt;.*)" |&lt;BR /&gt;
eval C_O=mvzip(Cert_num,Owner,"|") |&lt;BR /&gt;
eval C_O_I=mvzip(C_O,Issuer,"|") |&lt;BR /&gt;
eval C_O_I_S=mvzip(C_O_I,Serial_number,"|") |&lt;BR /&gt;
eval C_O_I_S_From=mvzip(C_O_I_S,ValidFrom,"|") |&lt;BR /&gt;
eval C_O_I_S_From_Until=mvzip(C_O_I_S_From,ValidUntil,"|") |&lt;BR /&gt;
mvexpand C_O_I_S_From_Until |&lt;/SHA1&gt;&lt;/MD5&gt;&lt;/VALIDUNTIL&gt;&lt;/VALIDFROM&gt;&lt;/SERIAL&gt;&lt;/ISSUER&gt;&lt;/OWNER&gt;&lt;/CERT&gt;&lt;/CERT&gt;&lt;/ENTRY&gt;&lt;/CREATION&gt;&lt;/ALIAS&gt;&lt;/ALIAS&gt;&lt;/STORETYPE&gt;&lt;/WAS&gt;&lt;/WAS&gt;&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;rex field=C_O_I_S_From_Until "^(?P&lt;NEW&gt;\d+)|(?P&lt;NEW&gt;[^|]+)|(?P&lt;NEW&gt;[^|]+)|(?P&lt;NEW&gt;[^|]+)|(?P&lt;NEW&gt;[^|]+)|(?P&lt;NEW&gt;.*)" |  dedup WAS_KeyStore_Location  Alias_Name New_Cert_num |&lt;BR /&gt;
table _time WAS_KeyStore_Location WAS_KeyStore_Name StoreType Alias Alias_Name Creation_Date Entry_Type Cert_Chain_Length New_Cert_num New_Owner New_Issuer New_Serial_number New_ValidUntil&lt;BR /&gt;
&lt;/NEW&gt;&lt;/NEW&gt;&lt;/NEW&gt;&lt;/NEW&gt;&lt;/NEW&gt;&lt;/NEW&gt;&lt;/P&gt;

&lt;P&gt;We didn't use reports or transforms in the end but are looking into doing that now to make this easier for non-Splunk gurus to use.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 10:52:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Troubleshooting-a-multi-line-multi-value-field-extraction/m-p/155950#M43878</guid>
      <dc:creator>skooby</dc:creator>
      <dc:date>2014-08-15T10:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting a multi-line, multi-value field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Troubleshooting-a-multi-line-multi-value-field-extraction/m-p/155951#M43879</link>
      <description>&lt;P&gt;Markdown is playing up:&lt;BR /&gt;
klzzwxh:0124 (etc.) should be underscore.  Too frustrated to try and fix it!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Aug 2014 11:01:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Troubleshooting-a-multi-line-multi-value-field-extraction/m-p/155951#M43879</guid>
      <dc:creator>skooby</dc:creator>
      <dc:date>2014-08-15T11:01:06Z</dc:date>
    </item>
  </channel>
</rss>

