I am attempting to build a exporting field that ArcSight can use to properly categorize. Here what I got:
REGEX = ($m)EventCode=(\d+)
FORMAT = devClassID::Microsoft-Windows-security-auditing:$1
WRITE_META = true
TRANSFORMS-DevExtract = devClassName
INDEXED = true
I need the result to be: Microsoft-Windows-security-auditing:4663 were as 4663 is pulled from EventCode in Splunk.
I have tried to build the transform just on my search forwarder, but it does not allow me to use the var $1
Seems the regex in your [devClassName] stanza is incorrect. Should be:
REGEX = (?m)^EventCode=(\d+)
The (?m)^ in the REGEX indicates a multi-line event that starts with EventCode. Please try again using the suggested regex statement.
Hope it will work. Thanks!