From IPS Event How can I extract only CVE value
XXXXDxxxre xxxrability (CVE-201x-00xx) (severity = Low)
I am writing:
rex "CVE-(?\d+\d+)"
but no event apprears
If you are using the TA Tenable do you need to create a props.conf file under and put the regex described by Giuseppe?
local karim$ pwd
/Applications/Splunk/etc/apps/Splunk_TA_nessus/local
local karim $ ls
inputs.conf
215:local karim $ more inputs.conf
[monitor:///Applications/Splunk/etc/apps/Splunk_TA_nessus/spool]
disabled = false
host = 127.0.0.1
sourcetype = CVE_2017
please advise
Thanks
Karim
Try this:
... | rex "CVE-(?<CVE>[^)]+)"
Hi rashid47010,
try
\(CVE-(?<CVE>[^\)]*)\)
you can sse in https://regex101.com/r/Pmk72R/1
Bye.
Giuseppe