Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

can some one help me in fixing this?

$
0
0
how might i incorporate regex into a like eval element in a search like this. This syntax does not work | eval product=case((signature LIKE "%Cipher%") OR (signature LIKE "%SMBv2 signing%") OR (signature LIKE "%Diffie-Hellman%") OR (signature LIKE "%Weak Cryptographic%") OR (signature LIKE "%SHA-%") OR (signature LIKE "%SWEET32%") OR (signature LIKE "%TLS/SSL%") OR (signature LIKE "%Certificate Is Invalid%") OR (signature LIKE "%protocol%"), "Cipher/Protocol/Cert", signature LIKE "%Java%", "Java", signature LIKE regex="[M][S][0-9][0-9][-][0-9][0-9][0-9]", "test", signature LIKE "%Apache%", "Apache", signature LIKE "%Apple%", "Apple", signature LIKE "%Cisco%", "Cisco", | search product=test | dedup signature | table signature product

Viewing all articles
Browse latest Browse all 47296

Trending Articles