Knowledge Management

How to match an array of CVEs into CIM CVE field?

shai
Explorer

Hello

My data is formatted as JSON and it contains a field named "cves" which contains an array of cve codes related to the event.  If I simply alias it to CVE then one row will contain all the CVES:

[props.conf]
FIELDALIAS-cve = cves as cve

 

I assume that in order for the data to be useful, I have to somehow break the array in such a way that each value will enter as a separate row.

Is this assumption correct? 
and if so, what is they way to do that in props.conf? 

Thank you

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...