Answer by warren for 10k Curl post request to splunk

It seems you’ve answered your own question – namely, the JSO blob you’re trying to POST is too big for the HEC to handle Split it into smaller chunks instead of trying to batch it all at once from User warren – Stack Overflow https://stackoverflow.com/questions/73158177/10k-curl-post-request-to-splunk/73208072#73208072 via IFTTT

Favorite tweets

@warrenmyers @SBCUnderground In the second link. https://t.co/MA0LXyzuNs — Cory Taylor (@corystaylor) Aug 2, 2022 from http://twitter.com/corystaylor via IFTTT

Favorite tweets

@warrenmyers @SBCUnderground Sure. https://t.co/fMEXRqIuhz https://t.co/n56VaogMIm — Cory Taylor (@corystaylor) Aug 2, 2022 from http://twitter.com/corystaylor via IFTTT

Favorite tweets

🌎 Aug. 2, 2022 🌍 πŸ”₯ 18 | Avg. Guesses: 7.61 πŸŸ₯πŸŸ₯πŸŸ₯πŸŸ₯πŸŸ₯πŸŸ₯πŸŸ₯🟩 = 8 #globle @warrenmyers — CatsFanInOhio πŸ‡ΊπŸ‡¦ (@michaeldf88) Aug 2, 2022 from http://twitter.com/michaeldf88 via IFTTT

Answer by warren for How to get particular field in splunk search for a nested JSON event

There are at least two approaches you can use If your sourcetype’s JSON is not being parsed properly by Splunk, this rex will pull it for you: | rex field=_raw "userid=(?<userid>\w+)" If it is being parsed properly, then you can probably get it by a variation on the theme of: | rename applicationTags{}.userid as userid …
Continue reading Answer by warren for How to get particular field in splunk search for a nested JSON event

Answer by warren for Regular expression to exclude UUID from capture group

Instead of trying to capture everything but a [possibly-present] UUID, just remove it instead (and then remove extra spaces): index=ndx sourcetype=srctp message=* | eval error_msg=replace(message,"\w{8}-\w{4}-\w{4}-\w{4}-\w{12}","") | eval error_msg=replace(error_msg,"\s+"," ") If you know that the UUID is always contained inside whitespace, you could make the first replace() more efficient thusly: | eval error_msg=replace(message,"\s\w{8}-\w{4}-\w{4}-\w{4}-\w{12}\s","") from User warren …
Continue reading Answer by warren for Regular expression to exclude UUID from capture group

”’A liberal will regularly watch a liberal news channel, continually reaffirming his liberal views. A conservative will regularly watch a conservative news channel, continually reaffirming his conservative views.”’ https://t.co/RxgjJA1J7e https://t.co/Yh3Wae7YpB

”’A liberal will regularly watch a liberal news channel, continually reaffirming his liberal views. A conservative will regularly watch a conservative news channel, continually reaffirming his conservative views.”’ https://t.co/RxgjJA1J7e https://t.co/Yh3Wae7YpB — Warren Myers 🐧🐿 (@warrenmyers) Aug 2, 2022 from Twitter https://twitter.com/warrenmyers August 02, 2022 at 04:04AM via IFTTT

#waffle193 0/5 🟩🟩🟩🟩🟩 🟩⬜🟩⬜🟩 🟩🟩🟩🟩🟩 🟩⬜🟩⬜🟩 🟩🟩🟩🟩🟩 πŸ”₯ streak: 39 πŸ₯ˆ #wafflesilverteam https://t.co/4doM5G9lQM

#waffle193 0/5 🟩🟩🟩🟩🟩 🟩⬜🟩⬜🟩 🟩🟩🟩🟩🟩 🟩⬜🟩⬜🟩 🟩🟩🟩🟩🟩 πŸ”₯ streak: 39 πŸ₯ˆ #wafflesilverteam https://t.co/4doM5G9lQM — Warren Myers 🐧🐿 (@warrenmyers) Aug 2, 2022 from Twitter https://twitter.com/warrenmyers August 01, 2022 at 08:12PM via IFTTT

🌎 Aug 1, 2022 🌍 πŸ”₯ 95 | Avg. Guesses: 7.03 🟨🟧πŸŸ₯πŸŸ₯πŸŸ₯πŸŸ₯🟩 = 7 #globle @michaeldf88

🌎 Aug 1, 2022 🌍 πŸ”₯ 95 | Avg. Guesses: 7.03 🟨🟧πŸŸ₯πŸŸ₯πŸŸ₯πŸŸ₯🟩 = 7 #globle @michaeldf88 — Warren Myers 🐧🐿 (@warrenmyers) Aug 1, 2022 from Twitter https://twitter.com/warrenmyers August 01, 2022 at 02:15PM via IFTTT

#waffle192 2/5 🟩🟩🟩🟩🟩 🟩⭐🟩⬜🟩 🟩🟩🟩🟩🟩 🟩⬜🟩⭐🟩 🟩🟩🟩🟩🟩 πŸ”₯ streak: 38 πŸ₯ˆ #wafflesilverteam https://t.co/4doM5G9lQM

#waffle192 2/5 🟩🟩🟩🟩🟩 🟩⭐🟩⬜🟩 🟩🟩🟩🟩🟩 🟩⬜🟩⭐🟩 🟩🟩🟩🟩🟩 πŸ”₯ streak: 38 πŸ₯ˆ #wafflesilverteam https://t.co/4doM5G9lQM — Warren Myers 🐧🐿 (@warrenmyers) Aug 1, 2022 from Twitter https://twitter.com/warrenmyers August 01, 2022 at 02:13PM via IFTTT

Answer by warren for Parsing last part of URL in Splunk

This regular expression will match the last part of the URL that ends with (case-insensitive) "exe", and that ends the string: | rex field=URL_Field "\/(?<exename>[^\/]+[eExXeE]{3})$" THe format is this: start with a front slash, then match everything that’s not a front slash that ends with "exe","EXE", etc, and that is at the end of the …
Continue reading Answer by warren for Parsing last part of URL in Splunk

Favorite tweets

#OTD 30 years ago STS-46 launched. This mission deployed ESA’s European Retrievable Carrier (EURECA) and the joint NASA/Italian Space Agency Tethered Satellite System (TSS). πŸ“Έ: NASA https://t.co/uAqK9GM3qf — Kennedy Space Center Visitor Complex (@ExploreSpaceKSC) Jul 31, 2022 from http://twitter.com/ExploreSpaceKSC via IFTTT