Forum Discussion
andrew_bryant
Aug 20, 2019Brass Contributor
Kusto question
Importing event logs into workspace that have a property like the following: <Param>1</Param><Param>2</Param><Param>3</Param><Param>4</Param><Param>5</Param> We are interested in the ...
- Aug 20, 2019
Are you asking about parsing? Example:
print txt = "<Param>1</Param><Param>2</Param><Param>3</Param><Param>4</Param><Param>5</Param>" | parse txt with *"<Param>2</" p2 "><Param>3"*
Go to Log Analytics and Run Query
txt p2 12345 Param
CliveWatson
Microsoft
Aug 20, 2019
Are you asking about parsing? Example:
print txt = "<Param>1</Param><Param>2</Param><Param>3</Param><Param>4</Param><Param>5</Param>"
| parse txt with *"<Param>2</" p2 "><Param>3"*
Go to Log Analytics and Run Query
txt | p2 |
---|---|
12345 |
Param |
andrew_bryant
Aug 22, 2019Brass Contributor
This was what I was looking for. Here is the query I ended up using:
Event
| parse ParameterXml with * "<Param>" SChannel "</Param><Param>" Username "</Param><Param>" domain "</Param><Param>" Workstation "</Param><Param>" channeltype
The event log source was NTLM operational log from DCs auditing NTLM requests.