Hi Splunkers!
I would like to extract detection_method value, "Access Protection"
file_name="HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM\", detection_method="Access Protection", vendor_action="IDS_ACTION_WOULD_BLOCK",
Thanks,
Manoj Kumar S
Hi All... Splunk newbie learning videos, for absolute beginners:
https://www.youtube.com/@SiemNewbies101/playlists
I have added 24 small videos of rex... Completely for Splunk newbies and beginners. hope this helps somebody, thanks.
| rex "detection_method=\"(?<detection_method>[^\"]+)\""