Hi Aitor
So is it one big string you want to parse the group name and the group domain from?
You can use python split() method to operate on the string if you know the delimiters.
Using split on the big string: string.split('Nombre de grupo:') would return 2 strings: the first string would contain the
the substring of the big string ending in 'Nombre de grupo:' and the second string would contain
the rest of the big string. You could then split the second string on 'Dominio de grups' and the first
string of that split would contain the group number with those extra characters that you need to parse out.
Then split second string again to get the group domain.
Does that help?
AnnMarie
------------------------------
AnnMarie Norcross
------------------------------
Original Message:
Sent: Wed February 12, 2020 06:14 AM
From: Aitor Vivanco Santa Cruz
Subject: Parsing from the incident payload table
Hello,
Im using the workflow "Qradar search for offense ID". I was able to extract the payload with UTF-8(payload) query. Then, i want to parse to extract some information from that payload and put as incident field. For example, the group name and group domain. Are remarked on the photo.
Is possible this exercise? It would help me a lot.
Table name: qradar_offense_event
Column name: payload
Thank you.
------------------------------
Aitor Vivanco Santa Cruz
------------------------------