All Apps and Add-ons

Why are you doing xml extractions manually via transforms?

dvb
Path Finder

In Splunk Add-on for Sysmon | Splunkbase (and some other Add-Ons) XML extractions are done via a lot of manual transforms (e.g. [sysmon-version] REGEX = <Version>(\d+)</Version> FORMAT = Version::$1). Why aren't you using KV_MODE = XML?

And could you please add the field query_type (Network_Resolution DM) and record_type values for A and AAAA records (which do NOT have a type: .. entry).

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I can't speak for the app's author, but one reason for using REGEX over KV_MODE is KV_MODE=xml only works on well-formed XML whereas REGEX often can extract fields from poorly-formatted XML events.

---
If this reply helps you, Karma would be appreciated.
0 Karma

dvb
Path Finder

Sorry, but I would like an answer from the author of the app (as I already know what you wrote).

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...