Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Transforms, REGEX and FORMAT issues

$
0
0
Hi, I want to use REGEX and FORMAT strings for an xml sample as given without using KV_MODE=xml So i am trying to use different regex to get hold of parsing fields but failing Please find the sample log for your reference and help -80.03107887624853,25.351308629611Interdiction6Assured2013-11-0304:40:00Infiltrators: Savanna Carrera, Gregoria Farías, Julina Abeyta, Mariquita Alonso, Urbano Briseño, Victoro Montano 3Raft-80.33045250710296,24.93574264936793Interdiction9Pompano2013-05-0404:22:000-80.30497342463124,24.07890526980327Rustic-79.94720757796837,24.82172611548247Interdiction12Barracuda2013-01-0105:22:00Infiltrators: Cristian Caballero, Vicenta Olivares, Leonides Cintrón, Ascencion Betancourt, Alanzo Arenas, Primeiro Sánchez, Serena Monroy, Madina Mojica, Consolacion Cordero, Faqueza Serrano, Grazia Quesada, Ivette Partida 0Rustic **Props.conf** [dreamcrusher] LINE_BREAKER = (\) TIME_PREFIX = TIME_FORMAT = %Y-%m-%d<\/ActionDate>[\r\n]\t+%H:%M:%S SHOULD_LINEMERGE = false MAX_DAYS_AGO = 2500 SEDCMD-aremoveheader = s/\<\?xml.*\s*\\s*//g SEDCMD-bremovefooter = s/\<\/dataroot\>//g REPORT-f = dream_attack KV_MODE = none **transforms.conf** [dream_attack] REGEX = (?m)^[^<]+.(.*?)\>([\S\s]*?)\<(?=[^\s]) FORMAT = $1::$2 Please suggest me why i am failing? Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>