Getting Data In

Parsing NetIQ DRA data from Windows Application Event Log

PebbleHG
Engager

I have some entries in WinEventLog://Application coming from NetIQ DRA. I couldn't find any add-ons for DRA on Splunkbase, so I'm reaching out for guidance on how to identify KV pairs within the Message field and extract them.

I can see that OOTB, Splunk has configs in etc/system/local/props.conf and transforms.conf that will extract KV pairs delimited by "=" or ":". In this case, the segregation is by spaces and/or tabs, and some of the keys (field names) have spaces as well, so I have to intelligently identify which portions are fields and which portions are values.

Compounding the issue is that some keys and values are on separate lines; for example, take a look at TransactionID and its value in my sample event. I also need to account for the potential of a field containing multiple values, such as "Member Added".

Any hints or guidance would be greatly appreciated.

Message=Action                   MemberAdd
ObjectType        Group
AssistantAdmin DOMAIN\joeblow-a
Target                   DOMAIN\LA.SVC
Domain Controller           SERVERNAME006
Member Added DOMAIN\SERVERNAME603$
Member Added DOMAIN\SERVERNAME604$
UTC Date
                                Wednesday, November 14, 2018
UTC Time
                                3:19:16 PM
AssistantAdmin
                OnePoint             OnePoint://CN=Admin\, Joe Blow,OU=Admin,OU=IT,OU=Users,OU=Town,DC=DOMAIN,DC=DOMAIN,DC=org
Member Added
                OnePoint                OnePoint://CN=SERVER603,OU=Prod,OU=Servers,OU=Computers,OU=Town,DC=DOMAIN,DC=DOMAIN,DC=org
                OnePoint                OnePoint://CN=SERVER604,OU=Prod,OU=Servers,OU=Computers,OU=Town,DC=DOMAIN,DC=DOMAIN,DC=org
Target
                OnePoint                OnePoint://CN=LA.SVC,OU=Prod,OU=Roles,OU=Security,OU=Groups,OU=Town,DC=DOMAIN,DC=DOMAIN,DC=org
TransactionID
                59E98034949344d98B716B11B00A722D
Sequence Number
                                0
ReturnCode       0x0
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...