Hello Splunkers, I need help with Network Security Group flow logs where each of the tuples should be a single event with other relevant data for an event. Sample.log _raw: {"time":"2021-10-25T16:17:50.8670851Z","systemId":"1c5751f4-8686-4ea5-82ee-173b64d401dd","macAddress":"xxxxxxxxxx","category":"NetworkSecurityGroupFlowEvent","resourceId":"/SUBSCRIPTIONS/A80612A2-33D6-47FF-817A-283E8BC8EDD2/RESOURCEGROUPS/C-SAP-EUS-NONPROD-01-INT-NETWORKING-RG/PROVIDERS/MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/DATA-INT-SUBNET-NSG","operationName":"NetworkSecurityGroupFlowEvents","properties":{"Version":2,"flows":[{"rule":"DefaultRule_AllowVnetOutBound","flows":[{"mac":"000D3A57248C","flowTuples":["1635178607,,10.123.2.28,46058,9997,T,O,A,E,1,74,1,60","1635178607,10.115.34.31,10.123.2.18,29128,9997,T,O,A,E,19,7292,16,1227","1635178609,10.115.34.31,10.119.241.5,26540,9997,T,O,A,E,47,54806,64,4395","1635178612,10.115.34.31,13.69.239.72,56024,443,T,O,A,B,,,,","1635178613,10.115.34.31,13.69.239.72,56026,443,T,O,A,B,,,,","1635178614,10.115.34.31,10.192.124.221,56488,80,T,O,A,B,,,,","1635178618,10.115.34.31,13.69.239.72,56024,443,T,O,A,E,8,1158,8,4897"]}]},{"rule":"UserRule_AzAppSubnet_access_toAzDBSubnet_Catch-all","flows":[{"mac":"000D3A57248C","flowTuples":["1635178635,10.115.32.28,10.115.34.31,54322,33015,T,I,A,B,,,,"]}]}]}} Json format category: NetworkSecurityGroupFlowEvent macAddress: xxxxxxxxxx operationName: NetworkSecurityGroupFlowEvents properties: { [-] Version: 2 flows: [ [-] { [-] flows: [ [-] { [-] flowTuples: [ [-] 1635172376,ip1,ip2,58636,443,T,O,A,E,6,1611,1,66 1635172377,ip1,ip2,27910,443,T,O,A,B,,,, 1635172377,ip1,ip2,59136,443,T,O,A,E,0,0,0,0 1635172378,ip1,ip2,56756,9997,T,O,A,B,,,, 1635172378,ip1,ip2,58686,9997,T,O,A,B,,,, 1635172379,ip1,ip2,53684,9997,T,O,A,B,,,, Result: Event 1: category: NetworkSecurityGroupFlowEvent macAddress: xxxxxxxxxx operationName: NetworkSecurityGroupFlowEvents properties: { [-] Version: 2 flows: [ [-] { [-] flows: [ [-] { [-] flowTuples: [ [-] 1635172376,ip1,ip2,58636,443,T,O,A,E,6,1611,1,66 Event2: category: NetworkSecurityGroupFlowEvent macAddress: xxxxxxxxxx operationName: NetworkSecurityGroupFlowEvents properties: { [-] Version: 2 flows: [ [-] { [-] flows: [ [-] { [-] flowTuples: [ [-] 1635172377,ip1,ip2,27910,443,T,O,A,B,,,, Thanks
... View more