...HAMPTS JODAC RL MTV 36X(4X60G). the rest doesn't appear. and also using regex with the command
| makemv tokenizer="(([[:alnum:]]+ )+([[:word:]]+))" productName
but the result is still the same....
How can I remove partial string of single line event and keep the rest by transforms.conf?
(Note: Originally I mistakenly said keep only 6k bytes. Sorry for the confusion)
I have syslog type o...
Hey folks,
So I have some logs coming in CEF format. Splunk is doing it's automatic field extraction, but when I look at the msg field, it only contains the first word of the message field.
S...
I am getting this error message when adding a phantom server using the new server configuration in the Phantom Add-on. Phantom Failed to communicate with user "" on Phantom server . Error: Unhashabl...
Pretty green with SOAR and haven't been able to find an good answer to this. All of our events in SOAR are generated by pulling them in from Splunk ES. This creates one artifact for each event...
The integrating Splunk with Arcsight document, states it is possible to feed Splunk with data coming straight from a Connector. Do you have any idea how this is possible?
The ArcSight website is n...
Hi team, I'm using Phantom to create playbooks and I would like to know how the find artifact is used when I create a phantom action block -> phantom app -> find artifacts action. Whe...
Imperva to Splunk - Unable to properly parse multiline events. Rawquery fields are appended with different timestamps for each newline.
EX:
Event 1
Jul 11 09:18:18 abc.xyz.com CEF: 0|I...