All Apps and Add-ons

Why are you doing xml extractions manually via transforms?

dvb
Path Finder

In Splunk Add-on for Sysmon | Splunkbase (and some other Add-Ons) XML extractions are done via a lot of manual transforms (e.g. [sysmon-version] REGEX = <Version>(\d+)</Version> FORMAT = Version::$1). Why aren't you using KV_MODE = XML?

And could you please add the field query_type (Network_Resolution DM) and record_type values for A and AAAA records (which do NOT have a type: .. entry).

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I can't speak for the app's author, but one reason for using REGEX over KV_MODE is KV_MODE=xml only works on well-formed XML whereas REGEX often can extract fields from poorly-formatted XML events.

---
If this reply helps you, Karma would be appreciated.
0 Karma

dvb
Path Finder

Sorry, but I would like an answer from the author of the app (as I already know what you wrote).

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...