<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to change current regex for field extraction of whole Set-Cookie from Squid events? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165101#M46901</link>
    <description>&lt;P&gt;What is the expected value for set_cookie (from the sample event)?&lt;/P&gt;</description>
    <pubDate>Thu, 31 Jul 2014 19:28:16 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-07-31T19:28:16Z</dc:date>
    <item>
      <title>How to change current regex for field extraction of whole Set-Cookie from Squid events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165098#M46898</link>
      <description>&lt;P&gt;Hi I am trying to extract multiple Set-Cookie from Squid Events.&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;REPORT-set_cookie = extract-set_cookies
REPORT-cookie = extract-cookies
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[extract-set_cookies]
REGEX = (?i)\\nSet-Cookie: (?P&amp;lt;set_cookie&amp;gt;[^\\]+)
MV_ADD = true

[extract-cookies]
REGEX = (?i)\\nCookie: (?P&amp;lt;cookie&amp;gt;[^\\]+)
MV_ADD = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But now, my field set_cookie has the following content:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;jive.security.context=
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here it cutted some content, because the original Set-Cookie from the Event looked like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Set-Cookie: jive.security.context=\"4Z2cMbTSRIsGjW.LTE=\"; Version=1; Max-Age=2592000; Expires=Fri, 29-Aug-2014 10:41:22 GMT; Path=/;HttpOnly
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What do i have to change in my Regex to get the whole Set-Cookie? &lt;/P&gt;

&lt;P&gt;Thanks in Advance for your help.&lt;BR /&gt;
Regards,&lt;BR /&gt;
Patrik&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 19:46:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165098#M46898</guid>
      <dc:creator>psidler</dc:creator>
      <dc:date>2014-07-30T19:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to change current regex for field extraction of whole Set-Cookie from Squid events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165099#M46899</link>
      <description>&lt;P&gt;You may want to post the whole event. The regex can be changed, but to do so, it will most likely require context.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 02:37:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165099#M46899</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2014-07-31T02:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to change current regex for field extraction of whole Set-Cookie from Squid events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165100#M46900</link>
      <description>&lt;P&gt;The whole Event looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;176 192.168.200.176:1096 TCP_MISS/200 779 GET &lt;A href="http://community.xmatters.com/__services/v2/rest/browserEvents/1406716809714" target="test_blank"&gt;http://community.xmatters.com/__services/v2/rest/browserEvents/1406716809714&lt;/A&gt;? - DIRECT/204.93.75.166 application/json "Accept: application/json, text/javascript, */*; q=0.01\r\nAccept-Language: de-ch\r\nReferer: &lt;A href="http://community.xmatters.com/welcome\r\nx-j-token:" target="test_blank"&gt;http://community.xmatters.com/welcome\r\nx-j-token:&lt;/A&gt; no-user\r\nx-requested-with: XMLHttpRequest\r\nContent-Type: application/json\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r\nHost: community.xmatters.com\r\nProxy-Connection: Keep-Alive\r\nCookie: jive.security.context=\"4Z2cMbTSRIsGjW.LTE=\"; JSESSIONID=350D94C62712F8858A.; BIGipServerm2s4c5-20-pool=1795401482.20480.0000; __utma=167379756.1989004756.1406722801.1406722801.1406722801.1; __utmb=167379756.1.10.1406722801; __utmc=167379756; __utmz=167379756.1406722801.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); lastDocument=Willkommen%20%7C%20xCommunity; _mkto_trk=id:178-CPU-592&amp;amp;token:_mch-xmatters.com-1406722802185-40555\r\n" "HTTP/1.1 200 OK\r\nDate: Wed, 30 Jul 2014 10:41:22 GMT\r\nServer: Apache-Coyote/1.1\r\nP3P: CP=\"CAO PSA OUR\"\r\nX-JIVE-USER-ID: -1\r\nContent-Type: application/json\r\nContent-Length: 76\r\nExpires: Wed, 30 Jul 2014 10:41:22 GMT\r\nCache-Control: no-store, no-cache, must-revalidate, private, max-age=0\r\nX-UA-Compatible: IE=edge\r\nX-JSL: D=4582 t=1406716882338765\r\nSet-Cookie: jive.security.context=\"4Z2cMbTSRIsGjW.LTE=\"; Version=1; Max-Age=2592000; Expires=Fri, 29-Aug-2014 10:41:22 GMT; Path=/;HttpOnly\r\nVary: User-Agent\r\nKeep-Alive: timeout=5, max=100\r\nConnection: Keep-Alive\r\n\r"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 31 Jul 2014 06:13:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165100#M46900</guid>
      <dc:creator>psidler</dc:creator>
      <dc:date>2014-07-31T06:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to change current regex for field extraction of whole Set-Cookie from Squid events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165101#M46901</link>
      <description>&lt;P&gt;What is the expected value for set_cookie (from the sample event)?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 19:28:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165101#M46901</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-31T19:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to change current regex for field extraction of whole Set-Cookie from Squid events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165102#M46902</link>
      <description>&lt;P&gt;That is what I expect:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;jive.security.context=\"4Z2cMbTSRIsGjW.LTE=\"; Version=1; Max-Age=2592000; Expires=Fri, 29-Aug-2014 10:41:22 GMT; Path=/;HttpOnly
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and that is what I get with my Regular Expression:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;jive.security.context=
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 31 Jul 2014 19:41:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165102#M46902</guid>
      <dc:creator>psidler</dc:creator>
      <dc:date>2014-07-31T19:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to change current regex for field extraction of whole Set-Cookie from Squid events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165103#M46903</link>
      <description>&lt;P&gt;One more question, I can see some "\r\n" in your logs. Are they literal character "\r\n" or they are new line but got converted here while pasting?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 19:47:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165103#M46903</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-31T19:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to change current regex for field extraction of whole Set-Cookie from Squid events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165104#M46904</link>
      <description>&lt;P&gt;They are literal character. They appear as \r\n in the message. In SPlunk they look the same as here in this post.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 19:50:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165104#M46904</guid>
      <dc:creator>psidler</dc:creator>
      <dc:date>2014-07-31T19:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to change current regex for field extraction of whole Set-Cookie from Squid events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165105#M46905</link>
      <description>&lt;P&gt;Give this try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search | rex "(?i)Set-Cookie:\s*(?P&amp;lt;set_cookie&amp;gt;((?:(?!\\\r).)*))"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;OR &lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EXTRACT-set_cookie = (?i)Set-Cookie:\s*(?P&amp;lt;set_cookie&amp;gt;((?:(?!\\r).)*))
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 31 Jul 2014 21:05:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165105#M46905</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-31T21:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to change current regex for field extraction of whole Set-Cookie from Squid events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165106#M46906</link>
      <description>&lt;P&gt;Thank you very much for your help. &lt;BR /&gt;
Now i receive the result I expect!&lt;/P&gt;

&lt;P&gt;Best Regards,&lt;BR /&gt;
Patrik&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 21:33:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-current-regex-for-field-extraction-of-whole-Set/m-p/165106#M46906</guid>
      <dc:creator>psidler</dc:creator>
      <dc:date>2014-07-31T21:33:50Z</dc:date>
    </item>
  </channel>
</rss>

