props.conf
[win_dns]
SEDCMD-win_dns = s/(\d+)/./g
SEDCMD-domainname = s/(\(\d\))/./g
EXTRACT-dns_name = (?i)] \w+\s+(?P
Example of dns_name
.hostname.domainname.org.
Can you help advise on how to remove the leading and trailing periods on dns_name ?
Thank you
Below configuration in props.conf
will fetch domain name.
[MSAD:NT6:DNS]
EXTRACT-question1 = \] (?<questiontype>\w+)\s+(?<questionname>.*)
EXTRACT-question2 = \] (?<questionname>[^\s]*)$
EVAL-domain = trim(replace(questionname, "(\([\d]+\))", "."),".")
Thank you
The best example I have is below, the field has a leading and trailing period. I would like remove. I can do it at search time using replace however if it can be done at index time it would be better.
.hostname.domainname.org.
'EXTRACT-dns_name = (?i)] w+s+\.(?P<dns_name>(.+))'
should get rid of the leading period. You should be able to get rid of both of them using 'EXTRACT-dns_name = (?i)] w+s+\.(?P<dns_name>(.+))\.<foo>'
where
It would be useful to see the raw event data that is being indexed, especially the parts immediately before and after the domain name.
Here you go Rich...
09/08/2015 23:58:56 1C78 PACKET 000000000A12C7D0 UDP Rcv 111.222.333.444 05da Q [0001 D NOERROR] A .www.bluecoat.com.
Were you able to figure this out?
Thank you
The best example I have is below, the field has a leading and trailing period. I would like remove. I can do it at search time using replace however if it can be done at index time it would be better.
.hostname.domainname.org.