<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help with REGEX in transforms.conf in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-with-REGEX-in-transforms-conf/m-p/160740#M45439</link>
    <description>&lt;P&gt;I have a requirement to route events to separate indexes based on two conditions.&lt;BR /&gt;
1) must contain the string &lt;LOGEVENTTYPECODE&gt;PI_EVENT&lt;/LOGEVENTTYPECODE&gt;&lt;BR /&gt;
2) Get the value contained in the &lt;BUSINESSDOMAINID&gt;value&lt;/BUSINESSDOMAINID&gt;&lt;/P&gt;

&lt;P&gt;The index it needs to be routed to will be the value of businessdomainid + -sec&lt;BR /&gt;
(ex. businessdomainid1-sec)&lt;/P&gt;

&lt;P&gt;How do I write my regex and format statement to have this work?&lt;/P&gt;

&lt;P&gt;Here's my transforms.conf so far&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Security]
SOURCE_KEY = _raw
DEST_KEY = _MetaData:Index
REGEX=(?m)\&amp;lt;BusinessDomainId\&amp;gt;(BusinessDomainId1|BusinessDomainId2|BusinessDomainId3)\&amp;lt;/BusinessDomainId\&amp;gt;|&amp;lt;LogEventTypeCode&amp;gt;PI_EVENT&amp;lt;/LogEventTypeCode&amp;gt;
FORMAT=$1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Sample event&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;ELLogInputMessage&amp;gt; 
        &amp;lt;Header&amp;gt; 
            &amp;lt;LogEventTypeCode&amp;gt;PI_EVENT&amp;lt;/LogEventTypeCode&amp;gt; 
            &amp;lt;LogSeverityCode&amp;gt;CRITICAL&amp;lt;/LogSeverityCode&amp;gt; 
            &amp;lt;LogEventDateTime&amp;gt;2014-05-06T23:59:59.9999999-05:00&amp;lt;/LogEventDateTime&amp;gt; 
        &amp;lt;/Header&amp;gt; 
        &amp;lt;SourceInformation&amp;gt; 
            &amp;lt;EAPMId&amp;gt;1&amp;lt;/EAPMId&amp;gt; 
            &amp;lt;HostMachineName&amp;gt;HostMachineName3&amp;lt;/HostMachineName&amp;gt; 
            &amp;lt;HostEnvironmentName&amp;gt;HostEnvironmentName3&amp;lt;/HostEnvironmentName&amp;gt; 
            &amp;lt;ComponentId&amp;gt;ComponentId3&amp;lt;/ComponentId&amp;gt; 
            &amp;lt;ComponentName&amp;gt;ComponentName3&amp;lt;/ComponentName&amp;gt; 
            &amp;lt;ApplicationEventCorrelationId&amp;gt;ApplicationEventCorrelationId3&amp;lt;/ApplicationEventCorrelationId&amp;gt; 
            &amp;lt;UserId&amp;gt;UserId1&amp;lt;/UserId&amp;gt; 
            &amp;lt;UserSrc&amp;gt;UserSrc1&amp;lt;/UserSrc&amp;gt; 
            &amp;lt;BusinessDomainId&amp;gt;BusinessDomainId1&amp;lt;/BusinessDomainId&amp;gt; 
            &amp;lt;BusinessDomainName&amp;gt;BusinessDomainName1&amp;lt;/BusinessDomainName&amp;gt; 
        &amp;lt;/SourceInformation&amp;gt; 
        &amp;lt;DataAccessInformation&amp;gt; 
            &amp;lt;DataCompId&amp;gt;DataCompId2&amp;lt;/DataCompId&amp;gt; 
            &amp;lt;TypeOfAccess&amp;gt;VIEW&amp;lt;/TypeOfAccess&amp;gt; 
            &amp;lt;SubjectOfInterest&amp;gt; 
                &amp;lt;SubjectId&amp;gt;SubjectId13&amp;lt;/SubjectId&amp;gt; 
                &amp;lt;SubjectName&amp;gt;SubjectName13&amp;lt;/SubjectName&amp;gt; 
                &amp;lt;SubjectDomainName&amp;gt;SubjectDomainName3&amp;lt;/SubjectDomainName&amp;gt; 
            &amp;lt;/SubjectOfInterest&amp;gt; 
            &amp;lt;AccessDateTime&amp;gt;2014-05-06T23:59:59.9999999-05:00&amp;lt;/AccessDateTime&amp;gt; 
        &amp;lt;/DataAccessInformation&amp;gt; 
        &amp;lt;DetailedLogInformation&amp;gt;anyType&amp;lt;/DetailedLogInformation&amp;gt;
&amp;lt;/ELLogInputMessage&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 12 May 2014 17:44:19 GMT</pubDate>
    <dc:creator>jedatt01</dc:creator>
    <dc:date>2014-05-12T17:44:19Z</dc:date>
    <item>
      <title>Help with REGEX in transforms.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-REGEX-in-transforms-conf/m-p/160740#M45439</link>
      <description>&lt;P&gt;I have a requirement to route events to separate indexes based on two conditions.&lt;BR /&gt;
1) must contain the string &lt;LOGEVENTTYPECODE&gt;PI_EVENT&lt;/LOGEVENTTYPECODE&gt;&lt;BR /&gt;
2) Get the value contained in the &lt;BUSINESSDOMAINID&gt;value&lt;/BUSINESSDOMAINID&gt;&lt;/P&gt;

&lt;P&gt;The index it needs to be routed to will be the value of businessdomainid + -sec&lt;BR /&gt;
(ex. businessdomainid1-sec)&lt;/P&gt;

&lt;P&gt;How do I write my regex and format statement to have this work?&lt;/P&gt;

&lt;P&gt;Here's my transforms.conf so far&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Security]
SOURCE_KEY = _raw
DEST_KEY = _MetaData:Index
REGEX=(?m)\&amp;lt;BusinessDomainId\&amp;gt;(BusinessDomainId1|BusinessDomainId2|BusinessDomainId3)\&amp;lt;/BusinessDomainId\&amp;gt;|&amp;lt;LogEventTypeCode&amp;gt;PI_EVENT&amp;lt;/LogEventTypeCode&amp;gt;
FORMAT=$1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Sample event&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;ELLogInputMessage&amp;gt; 
        &amp;lt;Header&amp;gt; 
            &amp;lt;LogEventTypeCode&amp;gt;PI_EVENT&amp;lt;/LogEventTypeCode&amp;gt; 
            &amp;lt;LogSeverityCode&amp;gt;CRITICAL&amp;lt;/LogSeverityCode&amp;gt; 
            &amp;lt;LogEventDateTime&amp;gt;2014-05-06T23:59:59.9999999-05:00&amp;lt;/LogEventDateTime&amp;gt; 
        &amp;lt;/Header&amp;gt; 
        &amp;lt;SourceInformation&amp;gt; 
            &amp;lt;EAPMId&amp;gt;1&amp;lt;/EAPMId&amp;gt; 
            &amp;lt;HostMachineName&amp;gt;HostMachineName3&amp;lt;/HostMachineName&amp;gt; 
            &amp;lt;HostEnvironmentName&amp;gt;HostEnvironmentName3&amp;lt;/HostEnvironmentName&amp;gt; 
            &amp;lt;ComponentId&amp;gt;ComponentId3&amp;lt;/ComponentId&amp;gt; 
            &amp;lt;ComponentName&amp;gt;ComponentName3&amp;lt;/ComponentName&amp;gt; 
            &amp;lt;ApplicationEventCorrelationId&amp;gt;ApplicationEventCorrelationId3&amp;lt;/ApplicationEventCorrelationId&amp;gt; 
            &amp;lt;UserId&amp;gt;UserId1&amp;lt;/UserId&amp;gt; 
            &amp;lt;UserSrc&amp;gt;UserSrc1&amp;lt;/UserSrc&amp;gt; 
            &amp;lt;BusinessDomainId&amp;gt;BusinessDomainId1&amp;lt;/BusinessDomainId&amp;gt; 
            &amp;lt;BusinessDomainName&amp;gt;BusinessDomainName1&amp;lt;/BusinessDomainName&amp;gt; 
        &amp;lt;/SourceInformation&amp;gt; 
        &amp;lt;DataAccessInformation&amp;gt; 
            &amp;lt;DataCompId&amp;gt;DataCompId2&amp;lt;/DataCompId&amp;gt; 
            &amp;lt;TypeOfAccess&amp;gt;VIEW&amp;lt;/TypeOfAccess&amp;gt; 
            &amp;lt;SubjectOfInterest&amp;gt; 
                &amp;lt;SubjectId&amp;gt;SubjectId13&amp;lt;/SubjectId&amp;gt; 
                &amp;lt;SubjectName&amp;gt;SubjectName13&amp;lt;/SubjectName&amp;gt; 
                &amp;lt;SubjectDomainName&amp;gt;SubjectDomainName3&amp;lt;/SubjectDomainName&amp;gt; 
            &amp;lt;/SubjectOfInterest&amp;gt; 
            &amp;lt;AccessDateTime&amp;gt;2014-05-06T23:59:59.9999999-05:00&amp;lt;/AccessDateTime&amp;gt; 
        &amp;lt;/DataAccessInformation&amp;gt; 
        &amp;lt;DetailedLogInformation&amp;gt;anyType&amp;lt;/DetailedLogInformation&amp;gt;
&amp;lt;/ELLogInputMessage&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 12 May 2014 17:44:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-REGEX-in-transforms-conf/m-p/160740#M45439</guid>
      <dc:creator>jedatt01</dc:creator>
      <dc:date>2014-05-12T17:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Help with REGEX in transforms.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-REGEX-in-transforms-conf/m-p/160741#M45440</link>
      <description>&lt;P&gt;Your current regex will match events that contain either &lt;LOGEVENT&gt; or &lt;BUSINESSDOMAINID&gt; tags, but necessarily both.  Try the following.&lt;/BUSINESSDOMAINID&gt;&lt;/LOGEVENT&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;REGEX=&amp;lt;LogEventTypeCode&amp;gt;PI_EVENT&amp;lt;/LogEventTypeCode&amp;gt;[\s\S]*&amp;lt;BusinessDomainId\&amp;gt;(BusinessDomainId1|BusinessDomainId2|BusinessDomainId3)\&amp;lt;/BusinessDomainId\&amp;gt;
FORMAT=$1-sec
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 12 May 2014 18:04:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-REGEX-in-transforms-conf/m-p/160741#M45440</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2014-05-12T18:04:10Z</dc:date>
    </item>
  </channel>
</rss>

