All Apps and Add-ons

Splunk_TA_microsoft_sysmon v1.0.1 incomplete RegistryValueData transform

alek_cybersec
Engager

I'd like to report an incomplete transform of RegistryValueData in Splunk_TA_microsoft_sysmon v1.0.1

Now it looks like:

[sysmon-registryvaluedata]
REGEX = <Data Name='Details'>\w+\s\((.+)\)</Data>
FORMAT = RegistryValueData::$1

So it works fine when Details contains: DWORD (0x00000001)

But when it is a string value, it doesn't make sense. 

What about this transform?

[sysmon-registryvaluedata]
REGEX = <Data Name='Details'>(?:([^(^)]*)|\w+\s\((.+)\))</Data>
FORMAT = RegistryValueData::$1

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...