Dashboards & Visualizations

RSA Archer Data into Splunk

anuremanan88
Explorer

Anyone integrated RSA Archer with Splunk? I am currently ingesting data from Archer via syslog. However i am finding difficulty in extracting fields as the logs are having xml data embedded along with Key value pairs. I am giving a sample log below. Anyone can help me in extracting the fields?

"
Mar 4 00:00:11 hostname vendor: RSA, product:Archer, version:1.x, ArcherVersion:6.x.x.x,ArcherInstance:Prod,LogSourceIdentifier:xx.xxx.xx.xx:x,eventtime:xx/xx/xxxx xx:xx:xx AM,eventid:00, ArcherLog:" UserId:1234 UserName:"xxxxxx, xxxxxx" LogDate:xx/xx/xxxx xx:xx:xx AM MethodName:FieldDefinitionManager.GetFieldDisplay InputParameter:fieldIds: OutputValues: Success:True

Tags (3)
0 Karma

anuremanan88
Explorer
Actual log sample is
"
    Mar  4 12:57:01 hostname vendor: RSA, product:Archer, version:1.0, ArcherVersion:6.4.10300.1028,ArcherInstance:prod,LogSourceIdentifier:10.240.88.47:0,eventtime:4/03/2019 4:57:01 AM,eventid:14, ArcherLog:" UserId:123 UserName:"123, 456" LogDate:4/03/2019 4:57:01 AM MethodName:FieldDefinitionManager.Get InputParameter:fieldIds<System.Collections.Generic.IList`1[System.Int32]>:<ROOT><V a="16106" /><V a="16133" /><V a="15730" /><V a="15735" /><V a="15733" /><V a="15736" /><V a="15743" /><V a="15748" /><V a="15751" /><V a="15754" /><V a="15749" /><V a="15747" /><V a="15746" /></ROOT> OutputValues:<ROOT><V a="15730" /><V a="15733" /><V a="15735" /><V a="15736" /><V a="15743" /><V a="15746" /><V a="13447" /><V a="15748" /><V a="15749" /><V a="15751" /><V a="15754" /><V a="16106" /><V a="16133" /></ROOT> Success:True

Mar  6 22:48:33 hostname vendor: RSA, product:Archer, version:1.0, ArcherVersion:6.4.10300.1028,ArcherInstance:TEST,LogSourceIdentifier:10.240.88.48:0,eventtime:2019-03-06 14:48:34,eventid:14, ArcherLog:" UserId:123 UserName:"assd, dcdfd" LogDate:2019-03-06 14:48:34 MethodName:ArcherTech.DataFeed.Workflows.ScheduledDataFeedWorkflow, ArcherTech.DataFeed, Version=6.4.10300.1028, Culture=neutral, PublicKeyToken=null InputParameter:3DataFeedId381 OutputValues:708ace45-2db1-4418-8612-30f25ad897ee Success:True "
0 Karma

anuremanan88
Explorer

"
Mar 4 12:44:11 hostname vendor: RSA, product:Archer, version:1.x, ArcherVersion:6.4.x.x,ArcherInstance:xxxx,LogSourceIdentifier:xx.xx.xx.xx:x,eventtime:4/03/2019 14:44:11 AM,eventid:10, ArcherLog:" UserId:1234 UserName:"xxxx xxxxx" LogDate:4/03/2019 14:44:11 AM MethodName:FieldDefinitionManager.GetFieldDisplay InputParameter:fieldIds: OutputValues: Success:True

0 Karma

sdchakraborty
Contributor

Hi,

You can use rex to extract the field. I am giving you a sample based on your log. Hope it will be useful. Please note that the regular expression is not full , I just extracted till ArcherLog field. Similar way you can extract for other fields.

| base search
| rex field=_raw "vendor:\s*(?<vendor>.*),\s*product:\s*(?<product>.*),\s*version:(?<version>.*),\s*ArcherVersion:(?<ArcherVersion>.*),\s*ArcherInstance:(?<ArcherInstance>.*),LogSourceIdentifier:(?<LogSourceIdentifier>.*),eventtime:(?<eventtime>.*),eventid:(?<eventid>.*),\s*ArcherLog:(?<ArcherLog>.*)\s*UserId"
0 Karma

anuremanan88
Explorer

Sorry that is not my actual log sample. The xml tags got removed while uploading to splunk portal.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...