Forum Discussion

Porter76's avatar
Porter76
Brass Contributor
Sep 08, 2023

Creating a Custom Column in a Data Table and populating from "AdditionalExtensions"

Our Zsclaer logs are pushed to our CommonSecurityLog data table. Zscaler pushes the device name to Sentinel, but for some reason it is not given its own column like the rest of the Data. It is just added to the AdditionalExtensions column.

 

Is it possible to parse just the "DeviceHostname=X-X-X-X" from "AdditionalExtensions" and add it to its own separate column labeled DeviceHostname?

 

 

Resources