<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7636955539235835573</id><updated>2025-10-10T13:54:05.050-05:00</updated><category term="VMware"/><category term="ESX"/><category term="ESXi"/><category term="Error"/><category term="Microsoft"/><category term="vCenter"/><category term="Quest"/><category term="View"/><category term="Best Practice"/><category term="Exchange"/><category term="New"/><category term="vRanger"/><category term="Backup"/><category term="2008r2"/><category term="Windows Server"/><category term="Monitoring"/><category term="Updates"/><category term="Vizioncore"/><category term="CentOS"/><category term="Graylog2"/><category term="2008"/><category term="Disaster Recovery"/><category term="Hyper-V"/><category term="Office"/><category term="Dell"/><category term="RedHat"/><category term="ThinApp"/><category term="syslog"/><category term="2003"/><category term="ElasticSearch"/><category term="FortiGate"/><category term="FortiNet"/><category term="Group Policy"/><category term="SBS 2008"/><category term="vConverter"/><category term="Brother"/><category term="Converter"/><category term="Entourage"/><category term="Graylog"/><category term="HP"/><category term="IIS"/><category term="IPv6"/><category term="Mac"/><category term="Outlook"/><category term="Permissions"/><category term="PowerCLI"/><category term="Replication"/><category term="SMTP"/><category term="SQL"/><category term="Scanner"/><category term="Script"/><category term="Sync"/><category term="VMware Tools"/><category term="Virus"/><category term="Win7"/><category term="Win8"/><category term="XP"/><category term="iPad"/><category term="vFoglight"/><title type='text'>Virtualize the World!</title><subtitle type='html'>Notes on server implementations and fixes for VMware, Microsoft, and other fun projects.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default?start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>74</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-7743599083542003972</id><published>2015-08-10T10:57:00.001-05:00</published><updated>2015-08-10T10:57:45.374-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Exchange"/><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>Exchange 2010 UM Old Voicemails</title><content type='html'>I ran into an issue in applying Exchange 2010 Service Pack 3 on an Unified Messaging server - the Prerequisite Check came back with the following error:&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: Verdana, sans-serif;&quot;&gt;Unified Messaging Role Prerequisites&lt;br /&gt;Failed&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Verdana, sans-serif;&quot;&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Verdana, sans-serif;&quot;&gt;Error:&lt;br /&gt;The Unified Messaging voice mail folder &#39;C:\Program Files\Microsoft\Exchange Server\V14\unifiedmessaging\voicemail&#39; isn&#39;t empty. This folder must be empty before upgrade can proceed.&lt;br /&gt;Click here for help... &lt;/span&gt;&lt;a href=&quot;http://technet.microsoft.com/en-US/library/ms.exch.err.default(EXCHG.141).aspx?v=14.3.123.3&amp;amp;e=ms.exch.err.Ex28883C&amp;amp;l=0&amp;amp;cl=cp&quot;&gt;&lt;span style=&quot;font-family: Verdana, sans-serif;&quot;&gt;http://technet.microsoft.com/en-US/library/ms.exch.err.default(EXCHG.141).aspx?v=14.3.123.3&amp;amp;e=ms.exch.err.Ex28883C&amp;amp;l=0&amp;amp;cl=cp&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
I went and looked, and indeed this folder was not empty. Looking at the dates on the voicemails, it was obvious that they were all old, and had been there for some time (the most recent was 6 months old). I believe there had been some previous delivery issues that had prevented them from being delivered to the proper mailbox. Since they were all old, I merely made a copy of them, and then removed them from this folder. Once the voicmail folder was empty, SP3 was able to continue installing without issue.&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/7743599083542003972/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2015/08/exchange-2010-um-old-voicemails.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/7743599083542003972'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/7743599083542003972'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2015/08/exchange-2010-um-old-voicemails.html' title='Exchange 2010 UM Old Voicemails'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-405084317631052730</id><published>2015-07-23T11:44:00.000-05:00</published><updated>2015-07-23T11:45:26.124-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="2003"/><category scheme="http://www.blogger.com/atom/ns#" term="IIS"/><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft"/><category scheme="http://www.blogger.com/atom/ns#" term="Script"/><category scheme="http://www.blogger.com/atom/ns#" term="SMTP"/><title type='text'>Dump SMTP Relay and Connection Info from IIS on 2003 via VBS</title><content type='html'>I had the need to pull all the SMTP related information from an old 2003 IIS server setup to do relaying. The specific information I was looking for was:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;IPs allowed to Relay&lt;/li&gt;
&lt;li&gt;IPs allowed to Connect&lt;/li&gt;
&lt;li&gt;Domains and if they had any SmartHost setup&lt;/li&gt;
&lt;/ul&gt;
Obviously, pulling this information via the GUI was not practical - you can only view 5 Relay IPs at a time, 2 Connection IPs at a time, and you have to manually check each domain&#39;s properties to verify SmartHost information.&lt;br /&gt;
&lt;br /&gt;
I was also unable to pull the information straight out of the Metabase Explorer, as I would still have to go to each domain separately, and then convert the Relay and Connection IPs from Hex.&lt;br /&gt;
&lt;br /&gt;
I looked around, but was unable to locate a ready-to-use VBScript that gave me what I wanted. I did find a script&lt;a href=&quot;http://classictriple.com/iis-export-iis-smtp-relayiplist/&quot; target=&quot;_blank&quot;&gt; here that dumped the IIS SMTP Relay IPs&lt;/a&gt;, so I started there and adapted to also get the Connection IPs (listed as IPSecurity). Then I found this site that detailed how to get the Domains and their settings. I added this to the script, and voila, I had what I wanted in a nice CSV file.&lt;br /&gt;
&lt;br /&gt;
To run the script, copy the below into notepad, save as &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;ExportIISSMTPSettings.vbs&lt;/span&gt; and run with the following command:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;cscript ExportIISSMTPSettings.vbs &amp;gt; IISSMTPServerSettings.csv&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;&#39;#####================================================================================ &lt;br /&gt;&#39;## Title: ExportIISSMTPSettings.vbs&lt;br /&gt;&#39;##&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;&#39;##&amp;nbsp; &lt;br /&gt;&#39;#####================================================================================&lt;br /&gt;&lt;br /&gt;Set objSMTP = GetObject(&quot;IIS://localhost/smtpsvc/1&quot;) &#39;Connect to the IIS Namespace, You can change the &quot;smtpsvc/1&quot; to fit your needs.&lt;br /&gt;Set objRelayIpList = objSMTP.Get(&quot;RelayIpList&quot;) &#39;Get the RelayIPListObject&lt;br /&gt;Set objIPSecurity = objSMTP.Get(&quot;IPSecurity&quot;) &#39;Get the IPSecurityObject&lt;br /&gt;&lt;br /&gt;&#39; *** Get Relay List&lt;br /&gt;&#39; GrantByDefault returns 0 when &quot;only the list below&quot; is set (false) and -1 when all except the list below is set(true)&lt;br /&gt;Wscript.echo &quot;Results will be display based on the Relay Restrictions Radio Buttion Selection&quot;&lt;br /&gt;Wscript.echo &quot;&amp;nbsp; o Only the list below&quot;&lt;br /&gt;Wscript.echo &quot;&amp;nbsp; o All Except the list below&quot;&lt;br /&gt;Wscript.echo &quot;-------------&quot;&lt;br /&gt;If objRelayIpList.GrantByDefault = true Then&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;All except the list below :&quot;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.echo &quot;-------------&quot;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objCurrentList = objRelayIpList.IPDeny&lt;br /&gt;Else&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;Only the list below :&quot;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.echo &quot;-------------&quot;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objCurrentList = objRelayIpList.IPGrant&lt;br /&gt;End If&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; count = 0&lt;br /&gt;For Each objIP in objCurrentList&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo objIP&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; count = count + 1&lt;br /&gt;Next&lt;br /&gt;If count = 0 Then&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;There were no IP Addresses Found&quot;&lt;br /&gt;End If&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;&#39; *** Get Connection Control List&lt;br /&gt;Wscript.echo &quot;Results will be display based on the Connection Control Radio Buttion Selection&quot;&lt;br /&gt;Wscript.echo &quot;&amp;nbsp; o Only the list below&quot;&lt;br /&gt;Wscript.echo &quot;&amp;nbsp; o All Except the list below&quot;&lt;br /&gt;Wscript.echo &quot;-------------&quot;&lt;br /&gt;If objIPSecurity.GrantByDefault = true Then&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;All except the list below :&quot;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.echo &quot;-------------&quot;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objCurrentList = objIPSecurity.IPDeny&lt;br /&gt;Else&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;Only the list below :&quot;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.echo &quot;-------------&quot;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; objCurrentList = objIPSecurity.IPGrant&lt;br /&gt;End If&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; count = 0&lt;br /&gt;For Each objIP in objCurrentList&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo objIP&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; count = count + 1&lt;br /&gt;Next&lt;br /&gt;If count = 0 Then&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;There were no IP Addresses Found&quot;&lt;br /&gt;End If&lt;br /&gt;Wscript.echo &quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;&#39; *** Get Domains and settings&lt;br /&gt;Wscript.echo &quot;Displaying list of Domains and settings&quot;&lt;br /&gt;Wscript.echo &quot;-------------&quot;&lt;br /&gt;Wscript.echo &quot;Route Actions:&quot;&lt;br /&gt;Wscript.echo &quot;2: Use DNS to route to this domain&quot;&lt;br /&gt;Wscript.echo &quot;4098: Forward all mail to smart host&quot;&lt;br /&gt;strComputer = &quot;.&quot;&lt;br /&gt;Set objWMIService = GetObject _&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (&quot;winmgmts:{authenticationLevel=pktPrivacy}\\&quot; _&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;amp; strComputer &amp;amp; &quot;\root\microsoftiisv2&quot;)&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;Set colItems = objWMIService.ExecQuery _&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (&quot;Select * from IIsSmtpDomainSetting&quot;)&lt;br /&gt;&lt;br /&gt;For Each objItem in colItems&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.echo &quot;&quot;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; For Each strTurn in objItem.AuthTurnList&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;Authentication Turn List: &quot; &amp;amp; strTurn&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;CSide Etrn Domains: &quot; &amp;amp; objItem.CSideEtrnDomains&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;Name: &quot; &amp;amp; objItem.Name&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;Relay For Authentication: &quot; &amp;amp; objItem.RelayForAuth&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;Relay IP List: &quot; &amp;amp; objItem.RelayIpList&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;Route Action: &quot; &amp;amp; objItem.RouteAction&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;Route Action String: &quot; &amp;amp; objItem.RouteActionString&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;Route Password: &quot; &amp;amp; objItem.RoutePassword&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wscript.Echo &quot;Route User Name: &quot; &amp;amp; objItem.RouteUserName&lt;br /&gt;Next&lt;/span&gt;&lt;/blockquote&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/405084317631052730/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2015/07/dump-smtp-relay-and-connection-info.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/405084317631052730'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/405084317631052730'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2015/07/dump-smtp-relay-and-connection-info.html' title='Dump SMTP Relay and Connection Info from IIS on 2003 via VBS'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-3667954468700602646</id><published>2015-06-02T09:00:00.005-05:00</published><updated>2015-06-02T09:00:54.930-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="2008r2"/><category scheme="http://www.blogger.com/atom/ns#" term="Error"/><category scheme="http://www.blogger.com/atom/ns#" term="Exchange"/><category scheme="http://www.blogger.com/atom/ns#" term="Monitoring"/><title type='text'>EventID 9385 on Exchange 2010 After Demoting DC</title><content type='html'>I recently demoted an old Domain Controller in an effort to move forward in my domain - it was a 32-bit 2008 Server, and all the rest of the DCs are 2008R2 or 2012R2. I don&#39;t have any needs today to move up AD functionality today (we are already on 2008 Forest and Domain Functionality), but it never hurts to be ready.&lt;br /&gt;
&lt;br /&gt;
After demoting an old Domain Controller, I recently started receiving Error 9385 on one of my Exchange 2010 Mailbox servers:&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;Log Name: &amp;nbsp; &amp;nbsp; &amp;nbsp;Application&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;Source: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;MSExchangeSA&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;Date: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6/2/2015 8:43:34 AM&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;Event ID: &amp;nbsp; &amp;nbsp; &amp;nbsp;9385&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;Task Category: General&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;Level: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Error&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;Keywords: &amp;nbsp; &amp;nbsp; &amp;nbsp;Classic&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;User: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;N/A&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;Computer: &amp;nbsp; &amp;nbsp; &amp;nbsp;MailboxSVR.internal.domain&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;Description:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;Microsoft Exchange System Attendant failed to read the membership of the universal security group &#39;/dc=domain/dc=internal/ou=Microsoft Exchange Security Groups/cn=Exchange Servers&#39;; the error code was &#39;8007203a&#39;. The problem might be that the Microsoft Exchange System Attendant does not have permission to read the membership of the group.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;If this computer is not a member of the group &#39;/dc=domain/dc=internal/ou=Microsoft Exchange Security Groups/cn=Exchange Servers&#39;, you should manually stop all Microsoft Exchange services, run the task &#39;add-ExchangeServerGroupMember,&#39; and then restart all Microsoft Exchange services.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;Event Xml:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;lt;Event xmlns=&quot;http://schemas.microsoft.com/win/2004/08/events/event&quot;&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;lt;System&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;Provider Name=&quot;MSExchangeSA&quot; /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;EventID Qualifiers=&quot;49152&quot;&amp;gt;9385&amp;lt;/EventID&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;Level&amp;gt;2&amp;lt;/Level&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;Task&amp;gt;1&amp;lt;/Task&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;Keywords&amp;gt;0x80000000000000&amp;lt;/Keywords&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;TimeCreated SystemTime=&quot;2015-06-02T13:43:34.000000000Z&quot; /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;EventRecordID&amp;gt;2199039&amp;lt;/EventRecordID&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;Channel&amp;gt;Application&amp;lt;/Channel&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;Computer&amp;gt;MailboxSVR.internal.domain&amp;lt;/Computer&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;Security /&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;lt;/System&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;lt;EventData&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;Data&amp;gt;/dc=com/dc=wmfingrp/dc=internal/ou=Microsoft Exchange Security Groups/cn=Exchange Servers&amp;lt;/Data&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;lt;Data&amp;gt;8007203a&amp;lt;/Data&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;nbsp; &amp;lt;/EventData&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace; font-size: x-small;&quot;&gt;&amp;lt;/Event&amp;gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
After doing some research, most articles said that you need to make sure that it&#39;s a member of the group, etc, but all of that was correct. There weren&#39;t any references to the old DC in anything I checked (DNS was pointed elsewhere, Domain controllers and Global catalog servers that this Exchange server used were pointed elsewhere, etc). But, I knew it had to do with my demoted DC. For some reason this particular Exchange server was really hoping that the DC would answer his requests. I didn&#39;t notice any other performance or user issues during this time, so it looks like the Exchange server was able to get his answer elsewhere after checking here.&lt;br /&gt;
&lt;br /&gt;
Once I was able to take a maintenance window, I rebooted the affected Exchange server, and all was well. It just needed to clear it&#39;s head after loosing it&#39;s good friend.&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/3667954468700602646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2015/06/eventid-9385-on-exchange-2010-after.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/3667954468700602646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/3667954468700602646'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2015/06/eventid-9385-on-exchange-2010-after.html' title='EventID 9385 on Exchange 2010 After Demoting DC'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-6598360482593810934</id><published>2015-05-06T08:45:00.002-05:00</published><updated>2015-05-06T08:46:18.782-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="FortiGate"/><category scheme="http://www.blogger.com/atom/ns#" term="FortiNet"/><category scheme="http://www.blogger.com/atom/ns#" term="Graylog"/><category scheme="http://www.blogger.com/atom/ns#" term="Graylog2"/><category scheme="http://www.blogger.com/atom/ns#" term="Monitoring"/><category scheme="http://www.blogger.com/atom/ns#" term="syslog"/><title type='text'>FortiGate Extractors for Graylog 1.0</title><content type='html'>Graylog is a nice opensource alternative to Splunk and other SIEM tools. I&#39;ve been using it for several years, and continue to make tweaks to improve its usefulness in my environment. I&#39;m excited now that it is on version 1.0 (and was renamed Graylog instead of Graylog2), and is a lot more stable.&lt;br /&gt;
&lt;br /&gt;
One of the tweaks I made a while back on a previous version was to create create a &lt;a href=&quot;http://www.virtualizetheworld.com/search/label/Graylog2&quot; target=&quot;_blank&quot;&gt;DRL extractor for FortiGate&lt;/a&gt; (a firewall made by FortiNet). I&#39;ve now updated this extractor so that you can import it using the new JSON format directly into the web interface (instead of having to create the DRL file, etc).&lt;br /&gt;
&lt;br /&gt;
To apply the extractors on Graylog, go to your FortiGate Input, and Import Extractors. The details on how to do that can be found on &lt;a href=&quot;https://www.graylog.org/resources/data-sources/&quot; target=&quot;_blank&quot;&gt;Graylog&#39;s site here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Here&#39;s the JSON script for the extractors:&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;{&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &quot;extractors&quot;: [&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sdevname=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;source&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTsource&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\saction=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;action&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTaction&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sapp=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;app&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTapp&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sappact=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;appact&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTappact&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sappcat=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;appcat&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTappcat&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sapplist=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;applist&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTapplist&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sattack=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;attack&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTattack&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sdevid=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;devid&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTdevid&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sdir=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;dir&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTdir&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sdstcountry=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;dstcountry&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTdstcountry&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sdstintf=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;dstintf&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTdstintf&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sdstip=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;dstip&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTdstip&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sdstport=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;dstport&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTdstport&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sdtype=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;dtype&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTdtype&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sduration=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;duration&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTduration&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\serror_reason=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;error_reason&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTerror_reason&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\seventtype=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;eventtype&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTeventtype&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sfile=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;file&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTfile&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sgroup=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;group&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTgroup&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\shostname=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;hostname&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGThostname&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sidentidx=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;identidx&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTidentidx&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sinit=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;init&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTinit&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\slocip=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;locip&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTlocip&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\slocport=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;locport&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTlocport&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\slogid=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;logid&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTlogid&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\smode=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;mode&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTmode&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\smsg=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;msg&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTmsg&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\soutintf=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;outintf&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGToutintf&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\speer_notif=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;peer_notif&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTpeer_notif&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\spolicyid=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;policyid&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTpolicyid&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sprofile=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;profile&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTprofile&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sprofiletype=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;profiletype&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTprofiletype&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sproto=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;proto&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTproto&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\squarskip=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;quarskip&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTquarskip&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\srcvdbyte=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;rcvdbyte&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTrcvdbyte&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\srcvdpkt=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;rcvdpkt&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTrcvdpkt&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sref=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;ref&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTref&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sremip=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;remip&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTremip&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sremport=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;remport&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTremport&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sresult=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;result&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTresult&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\srole=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;role&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTrole&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\ssentbyte=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;sentbyte&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTsentbyte&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\ssentpkt=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;sentpkt&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTsentpkt&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sservice=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;service&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTservice&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sservice=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;service&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTservice&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\ssrccountry=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;srccountry&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTsrccountry&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\ssrcintf=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;srcintf&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTsrcintf&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\ssrcip=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;srcip&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTsrcip&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\ssrcport=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;srcport&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTsrcport&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sstage=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;stage&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTstage&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sstatus=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;status&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTstatus&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sstatus=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;status&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTstatus&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\ssubtype=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;subtype&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTsubtype&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\stransport=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;transport&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTtransport&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\stype=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;type&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTtype&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\strandisp=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;trandisp&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTtrandisp&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\stransip=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;transip&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTtransip&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\suser=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;user&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTuser&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sutmaction=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;utmaction&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTutmaction&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sutmevent=(\\S+)\\s&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;utmevent&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTutmevent&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\svd=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;vd&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTvd&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;.+\\svirus=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;virus&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTvirus&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\svpntunnel=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;vpntunnel&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTvpntunnel&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sxauthgroup=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;xauthgroup&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTxauthgroup&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_type&quot;: &quot;none&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;condition_value&quot;: &quot;&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;converters&quot;: [],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;cursor_strategy&quot;: &quot;copy&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_config&quot;: {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;regex_value&quot;: &quot;^.+\\sxauthuser=\\\&quot;(.+?)\\\&quot;&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; },&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;extractor_type&quot;: &quot;regex&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;order&quot;: 0,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;source_field&quot;: &quot;message&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;target_field&quot;: &quot;xauthuser&quot;,&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &quot;title&quot;: &quot;FGTxauthuser&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; ],&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;&amp;nbsp; &quot;version&quot;: &quot;1.0.0&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;}&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/6598360482593810934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2015/05/fortigate-extractors-for-graylog-10.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/6598360482593810934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/6598360482593810934'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2015/05/fortigate-extractors-for-graylog-10.html' title='FortiGate Extractors for Graylog 1.0'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-3186883258171562437</id><published>2015-03-31T08:35:00.000-05:00</published><updated>2015-03-31T08:35:06.248-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Error"/><category scheme="http://www.blogger.com/atom/ns#" term="Exchange"/><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft"/><category scheme="http://www.blogger.com/atom/ns#" term="Outlook"/><category scheme="http://www.blogger.com/atom/ns#" term="Sync"/><title type='text'>Outlook Sync Issues</title><content type='html'>Synchronization issues are something that seem to plague any Exchange Admin. They come up for no reason, and go away for no reason. There have been a number of &lt;a href=&quot;http://thoughtsofanidlemind.com/2012/08/29/outlook-sync-issue/&quot; target=&quot;_blank&quot;&gt;posts&lt;/a&gt; on the issue over the years, most telling MS to go fix their issues.&lt;br /&gt;
&lt;br /&gt;
One particular issue that I&#39;ve seen recently is when moving a database from one Exchange 2010 DAG Member to another, the Sync Issues folder starts filling up with the following Synchronization Log messages:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:57 Synchronizer
Version 15.0.4701&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:57 Synchronizing
Mailbox &#39;User Name&#39;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:57 Synchronizing
Hierarchy&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:58 Synchronizing
server changes in folder &#39;Inbox&#39;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:58 Downloading from
server &#39;Client-Access-Server&#39;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:58  &amp;nbsp;&amp;nbsp;&amp;nbsp;1
item(s) added to offline folder&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;color: red; font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:58 Error
synchronizing folder&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;color: red; font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:58 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;[8004010F-501-8004010F-0]&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;color: red; font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:58 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;The client operation failed.&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;color: red; font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:58 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;Microsoft Exchange Information Store&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;color: red; font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:58 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;For more information on this failure, click
the URL below:&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;color: red; font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:58 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.microsoft.com/support/prodredirect/outlook2000_us.asp?err=8004010f-501-8004010f-0&quot;&gt;http://www.microsoft.com/support/prodredirect/outlook2000_us.asp?err=8004010f-501-8004010f-0&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Arial&amp;quot;,sans-serif; font-size: 9.0pt;&quot;&gt;7:57:58 Canceled&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
Checking all the normal locations, there is nothing wrong with the synchronization, yet every 5 minutes Outlook reports an error synchronizing. The above example is with Outlook 2013 on Exchange 2010 SP3 RU6, but I&#39;ve seen it through several Service Packs and Rollups. The issue also shows up on Outlook 2010.&lt;br /&gt;
&lt;br /&gt;
Looking through all the settings on the Exchange DAG Members, and the Client Access Server in use (which doesn&#39;t change during the failover), there is nothing out of the ordinary that might keep it from syncing.&lt;br /&gt;
&lt;br /&gt;
If I find a solution to this particular issue, I&#39;ll post it back here for posterity. Until then, this is merely another &quot;Microsoft, please fix you&#39;re sync problems&quot; blog.&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/3186883258171562437/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2015/03/outlook-sync-issues.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/3186883258171562437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/3186883258171562437'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2015/03/outlook-sync-issues.html' title='Outlook Sync Issues'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-6014537638390290918</id><published>2015-03-18T11:23:00.000-05:00</published><updated>2015-03-18T11:23:12.670-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Brother"/><category scheme="http://www.blogger.com/atom/ns#" term="Error"/><category scheme="http://www.blogger.com/atom/ns#" term="Permissions"/><category scheme="http://www.blogger.com/atom/ns#" term="Scanner"/><title type='text'>Brother ControlCenter4 Scanning Permissions</title><content type='html'>&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Brother ControlCenter4 Scanning to File requires certain permissions to write files to the folder. These permissions use the current logged in user permissions. To test that the write permissions are accessible, ControlCenter4 appears to write a .tmp file and create a temp folder. I say appears because I have not found any documentation on the subject.&lt;br /&gt;
&lt;br /&gt;
I ran across these required permissions because a scanner I support was trying to write to a network share that allowed Full Access MINUS the ability to create folders. Without the ability to create folders, it would drop a .tmp file in the folder on scan, and pop up an Unable to write the file to &quot;Destination Folder&quot;. error like the below:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5YWUrYz01ff2b1sZHHpAWdVWTUMSXODGlMH2KG-uLKFZch_Fo4sP4124eXkZH2aPxUIrs75GzTUibdlcHQVoO1Ov1tJq7O0bHN5HaGjG5ldOfIkza55XJFX-knk4wQnYQB_jq6Of4RTQ/s1600/brotherscanner.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5YWUrYz01ff2b1sZHHpAWdVWTUMSXODGlMH2KG-uLKFZch_Fo4sP4124eXkZH2aPxUIrs75GzTUibdlcHQVoO1Ov1tJq7O0bHN5HaGjG5ldOfIkza55XJFX-knk4wQnYQB_jq6Of4RTQ/s1600/brotherscanner.png&quot; height=&quot;158&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span id=&quot;goog_326033243&quot;&gt;&lt;/span&gt;&lt;span id=&quot;goog_326033244&quot;&gt;Once I assigned the user the ability to create folders in this directory (only), ControlCenter4 was able to scan properly.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/6014537638390290918/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2015/03/brother-controlcenter4-scanning.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/6014537638390290918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/6014537638390290918'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2015/03/brother-controlcenter4-scanning.html' title='Brother ControlCenter4 Scanning Permissions'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5YWUrYz01ff2b1sZHHpAWdVWTUMSXODGlMH2KG-uLKFZch_Fo4sP4124eXkZH2aPxUIrs75GzTUibdlcHQVoO1Ov1tJq7O0bHN5HaGjG5ldOfIkza55XJFX-knk4wQnYQB_jq6Of4RTQ/s72-c/brotherscanner.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-1648490705867525057</id><published>2015-02-18T09:15:00.000-06:00</published><updated>2015-02-18T09:16:10.192-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CentOS"/><category scheme="http://www.blogger.com/atom/ns#" term="ElasticSearch"/><category scheme="http://www.blogger.com/atom/ns#" term="Graylog2"/><category scheme="http://www.blogger.com/atom/ns#" term="Monitoring"/><title type='text'>Install ElasticSearch 1.3 on CentOS 6 for Graylog2 1.0</title><content type='html'>Graylog2&amp;nbsp;1.0 requires ElasticSearch 1.3 (or up). To fulfill this requirement, you will need to install ElasticSearch - I recommend on a separate server for environment growth. IOPS on your hard disk matters here.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
First, make sure your CentOS 6 is fully patched:&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;#yum update&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Then&amp;nbsp;install Java 1.7:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#yum install java&lt;/span&gt;&lt;br /&gt;
Make sure that it prompts you to install Java &lt;strong&gt;1.7&lt;/strong&gt; (look for the below text):&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;Installing:&lt;br /&gt;&amp;nbsp;java-1.7.0-openjdk&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Set up the &lt;a href=&quot;http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/setup-repositories.html&quot; target=&quot;_blank&quot;&gt;ElasticSearch Repositories&lt;/a&gt; and install Elasticsearch 1.3:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Import they key:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#&lt;span class=&quot;pln&quot;&gt;rpm &lt;/span&gt;&lt;span class=&quot;pun&quot;&gt;--&lt;/span&gt;&lt;span class=&quot;pln&quot;&gt;import https&lt;/span&gt;&lt;span class=&quot;pun&quot;&gt;://&lt;/span&gt;&lt;span class=&quot;pln&quot;&gt;packages&lt;/span&gt;&lt;span class=&quot;pun&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;pln&quot;&gt;elasticsearch&lt;/span&gt;&lt;span class=&quot;pun&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;pln&quot;&gt;org&lt;/span&gt;&lt;span class=&quot;pun&quot;&gt;/&lt;/span&gt;&lt;span class=&quot;pln&quot;&gt;GPG&lt;/span&gt;&lt;span class=&quot;pun&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;pln&quot;&gt;KEY&lt;/span&gt;&lt;span class=&quot;pun&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;pln&quot;&gt;elasticsearch&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;span class=&quot;pln&quot;&gt;&lt;br /&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: inherit;&quot;&gt;Create a new repository file in &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;/etc/yum.repos.d/&lt;/span&gt; named &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;elasticsearch.repo&lt;/span&gt; with the following contents:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;[elasticsearch-1.3]&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;name=Elasticsearch repository for 1.3.x packages&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;baseurl=http://packages.elasticsearch.org/elasticsearch/1.3/centos&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;gpgcheck=1&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;gpgkey=http://packages.elasticsearch.org/GPG-KEY-elasticsearch&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;enabled=1&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
Install ElasticSearch:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;#yum install elasticsearch&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
Add&amp;nbsp;ElasticSearch to boot process:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;#chkconfig --add elasticsearch&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Stop the elasticsearch service so that we can update the cluster name:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#service elasticsearch stop&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Edit the &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;/etc/elasticsearch/elasticsearch.yml&lt;/span&gt; file to update your &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;cluster.name&lt;/span&gt; variable. Ex:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;cluster.name: graylog2_production&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Update any additional settings needed and save the file. I recommend updating the &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;path.data&lt;/span&gt; and &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;path.logs&lt;/span&gt; to custom directories.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Start the elasticsearch service and set it to run on startup:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#service elasticsearch start&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#chkconfig elasticsearch on&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Check your logs to make sure that it started properly and joined the cluster (if there is an existing one).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For Graylog2, the recommended settings are also to increase the open file limit to at least 64000 as seen in the&amp;nbsp;&lt;a href=&quot;https://www.graylog.org/documentation/setup/elasticsearch/&quot; target=&quot;_blank&quot;&gt;Configuring and&amp;nbsp;tuning&amp;nbsp;Elasticsearch&lt;/a&gt;&amp;nbsp;documentation. I did this by increasing the max number of ulimit open file below.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Edit &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;/etc/sysctl.conf&lt;/span&gt; and add the following line at the end:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;fs.file-max = 65536&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Save the file. Next edit &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;/etc/security/limits.conf&lt;/span&gt; and add the following lines:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; soft&amp;nbsp;&amp;nbsp;&amp;nbsp; nproc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65535&lt;br /&gt;*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hard&amp;nbsp;&amp;nbsp;&amp;nbsp; nproc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65535&lt;br /&gt;*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; soft&amp;nbsp;&amp;nbsp;&amp;nbsp; nofile&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65535&lt;br /&gt;*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hard&amp;nbsp;&amp;nbsp;&amp;nbsp; nofile&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65535&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Save the file and restart the server.&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#shutdown -r now&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Once restarted, verify that the max open file ulimit has been increased.&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;# ulimit -a&lt;br /&gt;core file size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (blocks, -c) 0&lt;br /&gt;data seg size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (kbytes, -d) unlimited&lt;br /&gt;scheduling priority&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-e) 0&lt;br /&gt;file size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (blocks, -f) unlimited&lt;br /&gt;pending signals&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-i) 30507&lt;br /&gt;max locked memory&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (kbytes, -l) 64&lt;br /&gt;max memory size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (kbytes, -m) unlimited&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;open files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-n) 65535&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;pipe size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (512 bytes, -p) 8&lt;br /&gt;POSIX message queues&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (bytes, -q) 819200&lt;br /&gt;real-time priority&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-r) 0&lt;br /&gt;stack size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (kbytes, -s) 10240&lt;br /&gt;cpu time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (seconds, -t) unlimited&lt;br /&gt;max user processes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-u) 65535&lt;br /&gt;virtual memory&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (kbytes, -v) unlimited&lt;br /&gt;file locks&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-x) unlimited&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additional recommended settings are to increase the &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;ES_HEAP_SIZE&lt;/span&gt;. I did this by editing &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;/etc/init.d/elasticsearch&lt;/span&gt; and adding the following line after &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;checkJava&lt;/span&gt; under &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;start()&lt;/span&gt;:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;ES_HEAP_SIZE=2g&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
They recommend that you leave 50% of your memory for other system functions, and I had 4 Gig of RAM, hence the 2g setting.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/1648490705867525057/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2015/02/install-elasticsearch-13-on-centos-6.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/1648490705867525057'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/1648490705867525057'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2015/02/install-elasticsearch-13-on-centos-6.html' title='Install ElasticSearch 1.3 on CentOS 6 for Graylog2 1.0'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-6234935446731279033</id><published>2014-10-10T07:11:00.000-05:00</published><updated>2014-10-10T07:19:07.059-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Error"/><category scheme="http://www.blogger.com/atom/ns#" term="vCenter"/><category scheme="http://www.blogger.com/atom/ns#" term="VMware"/><title type='text'>Deploying vCOPS 5.x in vSphere Essentials Plus</title><content type='html'>&lt;br /&gt;
VMware vCenter Operations Manager 5.x has a requirement for DRS (Distributed Resource Schedule) to be able to be deployed in a cluster - this is because it is deployed as a vApp, and vApps require DRS.&lt;br /&gt;
&lt;br /&gt;
If you are attempting to install vCOPS on vSphere Essentials, Essentials Plus, or Standard, you will discover that you don&#39;t have license for DRS. VMware released &lt;a href=&quot;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=2013695&quot; target=&quot;_blank&quot;&gt;this article&lt;/a&gt; as the resolution to the problem. Here are the steps that they detailed:&lt;br /&gt;
&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
&lt;span itemprop=&quot;articleBody&quot;&gt;To deploy vCenter Operations Manager in a 
vCenter Server environment with an Essentials Plus or Standard cluster 
of three ESX hosts:&lt;/span&gt;&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Remove one of the ESX hosts from the cluster so that it resides directly under the parent datacenter. &lt;/li&gt;
&lt;li&gt;On that ESX host, deploy the vCenter Operations Manager vApp, specifying static IP addresses.&lt;/li&gt;
&lt;li&gt;Power on the vApp before moving the host back into the cluser to ensure IP settings are picked up.&lt;/li&gt;
&lt;li&gt;License the solution in vCenter.&lt;/li&gt;
&lt;li&gt;Move the ESX host with vCenter Operations back into the cluster.&lt;/li&gt;
&lt;/ol&gt;
&lt;b&gt;Note&lt;/b&gt;: Static IP addresses are required.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Warning&lt;/b&gt;:
 The steps above dissolve the vApp container and an error is displayed. 
Disregard the error message and continue moving the host into the 
cluster.&lt;br /&gt;
&lt;br /&gt;
Moving the ESX host with the vCenter Operations vApp 
back into the cluster results in the addition of the two virtual 
machines (the UI virtual machine and the Analytics virtual machine) to 
the cluster, without the vApp container. vCenter Operations Manager 5.x 
continues to function normally when this happens.&lt;br /&gt;
---&lt;br /&gt;
&lt;br /&gt;
Also, in case you need it, the default logins for vCOPS are:&lt;br /&gt;
Default Administration:&lt;br /&gt;
admin&lt;br /&gt;
admin&lt;br /&gt;
&lt;br /&gt;
Default Root Login:&lt;br /&gt;
root&lt;br /&gt;
vmware&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/6234935446731279033/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2014/10/deploying-vcops-5x-in-vsphere.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/6234935446731279033'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/6234935446731279033'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2014/10/deploying-vcops-5x-in-vsphere.html' title='Deploying vCOPS 5.x in vSphere Essentials Plus'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-7130402891668760109</id><published>2014-09-08T09:47:00.000-05:00</published><updated>2014-09-08T09:47:03.274-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Error"/><category scheme="http://www.blogger.com/atom/ns#" term="Exchange"/><title type='text'>User exceeded the maximum of 250 objects of type &quot;objtMessage&quot;.</title><content type='html'>&lt;br /&gt;I have users that are regularly exceeding 250 objtMessage objects in Exchange 2010. What this really means is that the user has over 250 Messages open at once. While this seems high, when you consider third party tools and other such things, 250 is really not that much. I actually have a couple of users that regularly spike over 500 on a daily basis.&lt;br /&gt;
&lt;br /&gt;
Whenever this behavior exhibits itself, it&#39;s in the form of ERROR in the Application log with EventID 9646. The text reads:&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;Mapi session &quot;64807ed0-b1b3-4938-92e3-b9dbd9cfe67b: /o=Company/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/cn=Recipients/cn=User Name&quot; exceeded the maximum of 250 objects of type &quot;objtMessage&quot;. &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
The default setting for this (and other open item limits in Exchange 2010) is detailed in &lt;a href=&quot;http://technet.microsoft.com/en-us/library/ff477612%28v=exchg.141%29.aspx&quot; target=&quot;_blank&quot;&gt;Microsoft&#39;s Exchange Store Limits article&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
To change from the default settings, open the registry on your Mailbox Server, and navigate to the following key:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;HKLM\SYSTEM\ConcurrentControlSet\services\MSExchangeIS\ParametersSystem\MaxObjsPerMapiSession&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Update/create the DWORD named &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;objtMessage&lt;span style=&quot;font-family: Arial,Helvetica,sans-serif;&quot;&gt; &lt;/span&gt;&lt;/span&gt;and give it the decimal value that you need (up it to 500).&lt;br /&gt;
&lt;br /&gt;
Don&#39;t forget if you are in a DAG to repeat the registry entries on all Mailbox Servers.&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/7130402891668760109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2014/09/user-exceeded-maximum-of-250-objects-of.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/7130402891668760109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/7130402891668760109'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2014/09/user-exceeded-maximum-of-250-objects-of.html' title='User exceeded the maximum of 250 objects of type &quot;objtMessage&quot;.'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-7006195506706937978</id><published>2014-07-30T12:46:00.000-05:00</published><updated>2014-07-30T12:49:17.885-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="2008r2"/><category scheme="http://www.blogger.com/atom/ns#" term="Error"/><category scheme="http://www.blogger.com/atom/ns#" term="Group Policy"/><title type='text'>The symbolic link cannot be followed</title><content type='html'>When you setup symbolic links on a server that point to another server, you will by default run into the inability for a client computer to follow the links with the following error:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;The symbolic link cannot be followed because its type is disabled.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMUS0kkGpbpfwJwRabLA16U0MqhyU3YfTMylFgalI8seAxeP_1XYpf_2frvrFbfs3xbxdqdDa6ubME-aX4vYwJTRlePH_OKpn86ybrZVCCpNYO_n2dPSaiv1FiKbqO_l8RFD8ORyUJ6oI/s1600/symboliclinkerror.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMUS0kkGpbpfwJwRabLA16U0MqhyU3YfTMylFgalI8seAxeP_1XYpf_2frvrFbfs3xbxdqdDa6ubME-aX4vYwJTRlePH_OKpn86ybrZVCCpNYO_n2dPSaiv1FiKbqO_l8RFD8ORyUJ6oI/s1600/symboliclinkerror.png&quot; height=&quot;111&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This is because the ability to traverse from one remote system to another across the symbolic link is disabled by default. You can see what is disabled and what is enabled on a computer by running the &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;fsutil &lt;/span&gt;command:&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;gt;fsutil behavior query eymlinkevaluation&lt;br /&gt;Local to local symbolic links are enabled.&lt;br /&gt;Local to remote symbolic links are enabled.&lt;br /&gt;Remote to local symbolic links are disabled.&lt;br /&gt;Remote to remote symbolic links are disabled.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
You have two methods to enable this - enable it locally on each machine, or enable it via Group Policy.&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
Local&lt;/h3&gt;
The downsides to enabling it locally are obvious, but sometimes you just need it on one stubborn computer *right now* and can&#39;t wait for GP. To enable Remote to Remote symbolic links, run the following command:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;fsutil behavior set symlinkevaluation R2R:1&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Similarly, you can change the settings for Local to Local (&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;L2L&lt;/span&gt;), Local to Remote (&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;L2R&lt;/span&gt;), and Remote to Local (&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;R2L&lt;/span&gt;) by using 1 for enabled and 0 for disabled.&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
Group Policy&lt;/h3&gt;
To enable (or disable) Remote to Remote symbolic links in Group Policy, create a new GPO Policy (or edit a current one), and edit it. Navigate to:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;Computer Configuration -&amp;gt; Administrative Templates -&amp;gt; System -&amp;gt; Filesystem&lt;/span&gt;&lt;br /&gt;
You can then set the settings how you want in &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;Selectively allow the evaluation of a symbolic link&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCEkrRJrwuXWfQHEy_D_kwc2RYMxyw4Ec9P9bN965LWeYULAQVt6PQhfybU3gOfzwZCDRg4nN6HCU4w9K1NI2jbRtZl4uBkq73UMv5v6_wotG8gvKgjZ7h06bUXPiNG-F327jMZJH3_Po/s1600/SymbolicLinkGPO.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCEkrRJrwuXWfQHEy_D_kwc2RYMxyw4Ec9P9bN965LWeYULAQVt6PQhfybU3gOfzwZCDRg4nN6HCU4w9K1NI2jbRtZl4uBkq73UMv5v6_wotG8gvKgjZ7h06bUXPiNG-F327jMZJH3_Po/s1600/SymbolicLinkGPO.png&quot; height=&quot;293&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Once you&#39;ve created your new GPO, test it and validate that it is successfully applied using &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;gpresult /R&lt;/span&gt; and &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;rsop&lt;/span&gt;.</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/7006195506706937978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2014/07/the-symbolic-link-cannot-be-followed.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/7006195506706937978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/7006195506706937978'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2014/07/the-symbolic-link-cannot-be-followed.html' title='The symbolic link cannot be followed'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMUS0kkGpbpfwJwRabLA16U0MqhyU3YfTMylFgalI8seAxeP_1XYpf_2frvrFbfs3xbxdqdDa6ubME-aX4vYwJTRlePH_OKpn86ybrZVCCpNYO_n2dPSaiv1FiKbqO_l8RFD8ORyUJ6oI/s72-c/symboliclinkerror.png" height="72" width="72"/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-7633232674861213946</id><published>2014-07-28T11:43:00.000-05:00</published><updated>2015-01-09T11:24:41.856-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Group Policy"/><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft"/><category scheme="http://www.blogger.com/atom/ns#" term="Win7"/><category scheme="http://www.blogger.com/atom/ns#" term="Win8"/><category scheme="http://www.blogger.com/atom/ns#" term="Windows Server"/><title type='text'>How to use Group Policy to allow the users to chose any screensaver except (None)</title><content type='html'>I just found one of the most beautiful Group Policies that I&#39;ve ever come across:&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.grouppolicy.biz/2010/07/how-to-use-group-policy-to-allow-the-users-to-chose-any-screensaver-except-none/&quot; target=&quot;_blank&quot;&gt;How to use Group Policy to allow the users to chose any screensaver except (None)&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
This post is from Group Policy Central, and is 4 years old, but I&#39;ve verified that it works properly with Windows 7 and 8, and is just a beautifully done Group Policy. Thanks Kevin for creating it and thank Alan for sharing.&lt;br /&gt;
&lt;br /&gt;
The below is excerpts from the posting:&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Step 1.&lt;/strong&gt; Edit a Group Policy Object (GPO) that is targeted to the users accounts you wan to apply this policy&lt;br /&gt;
&lt;strong&gt;Step 2&lt;/strong&gt;. Navigate to User Configuration &amp;gt; Preferences &amp;gt; Windows Settings &amp;gt; Registry then from the menu click on Action &amp;gt; New &amp;gt; Registry Item&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjeoGgYvidxMNjSgnOq_aPHXfS8ZEaW2a5DO4GRMHxi8gJaqTNPs7Jjaj9ly2XYM4mPFjckReCqdBjOrG5l11z5vZv1fuU5w_klNklewHVWiO0ZyvxIStEP6VB75coTgM1Cgrhd9z5Ugtk/s1600/p1.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjeoGgYvidxMNjSgnOq_aPHXfS8ZEaW2a5DO4GRMHxi8gJaqTNPs7Jjaj9ly2XYM4mPFjckReCqdBjOrG5l11z5vZv1fuU5w_klNklewHVWiO0ZyvxIStEP6VB75coTgM1Cgrhd9z5Ugtk/s1600/p1.PNG&quot; height=&quot;640&quot; width=&quot;504&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;strong&gt;Step 3.&lt;/strong&gt; Select “Update” from the Action then type “Control Panel\Desktop” in the Key Path: text field then type “SCRNSAVE.EXE”&amp;nbsp; in the Value Name text field and “C:\Windows\System32\scrnsave.scr” in the Value data: text field.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7lNcEm-lmZySt_z3hoxdRQ-ZoC540nwXbZAz1NlTtKLCrI6LBu97saMxMW3JW0m2EZ7jYsNTYLPMMY5xANARioEEjoIE1w6zVIiVY2q9xkdrS-IszcPI6cTJqCGvKZFhFGkLU3NRgOg0/s1600/p2.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7lNcEm-lmZySt_z3hoxdRQ-ZoC540nwXbZAz1NlTtKLCrI6LBu97saMxMW3JW0m2EZ7jYsNTYLPMMY5xANARioEEjoIE1w6zVIiVY2q9xkdrS-IszcPI6cTJqCGvKZFhFGkLU3NRgOg0/s1600/p2.PNG&quot; height=&quot;640&quot; width=&quot;578&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;strong&gt;Step 4.&lt;/strong&gt; Click on the Common tab and then tick “Item-level targeting” and then click the “Targeting…” button.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5yCdFXnD3zGa5nTl1e0p1wL0zpRyo3A5g-yOZ23U-D1M7odEQ0oOekNKx7m5VVrN2GPoaAKc1WXBcwj0Fe9VYjmdHM2czI8Y1BpOTG-bFZNFfr7pmj9jafvzz2Z0CF3p4cBl0bwFjASs/s1600/p3.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5yCdFXnD3zGa5nTl1e0p1wL0zpRyo3A5g-yOZ23U-D1M7odEQ0oOekNKx7m5VVrN2GPoaAKc1WXBcwj0Fe9VYjmdHM2czI8Y1BpOTG-bFZNFfr7pmj9jafvzz2Z0CF3p4cBl0bwFjASs/s1600/p3.PNG&quot; height=&quot;640&quot; width=&quot;576&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
Now we will target the screen saver to apply only when the “HKCU\Control Panel\Desktop\SCRNSAVE.EXE” registry key does NOT exist as this means the screen saver has been configured to “(None)”.&lt;br /&gt;
&lt;strong&gt;Step 5.&lt;/strong&gt; Click on “New Item” then the “Registry Match” option.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeIt7rcGfZOZXyBtsjrDs2z_W6a7jtMy2CDgiFwL-qcZyktYnk_nIvOV6tda1TmEghm06rHmnYyWzADdZLr3aJno30nFcplo0DqGFcyIYOBvY692yAYQoqS1TxNJFZ369vKCujDVUHuzM/s1600/p4.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeIt7rcGfZOZXyBtsjrDs2z_W6a7jtMy2CDgiFwL-qcZyktYnk_nIvOV6tda1TmEghm06rHmnYyWzADdZLr3aJno30nFcplo0DqGFcyIYOBvY692yAYQoqS1TxNJFZ369vKCujDVUHuzM/s1600/p4.PNG&quot; height=&quot;640&quot; width=&quot;454&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;strong&gt;Step 6.&lt;/strong&gt; Select the “Value exists” Match type” then type “Control Panel\Desktop” in the key path field and then type “SCRNSAVE.EXE” in the value name field &lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYcQOZqOKdEUb63HyhZO4nx4_DcUxJ9Irex2tHxS6rNWBBmQHKvkhkAgbXsOSUcojGIwaXKrZ7tz_61D6m6x6QOgAmZK00x3H1s2beHNUZolh2yelvqYX6-wjjST4uElQuqUg-WeIni30/s1600/p5.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYcQOZqOKdEUb63HyhZO4nx4_DcUxJ9Irex2tHxS6rNWBBmQHKvkhkAgbXsOSUcojGIwaXKrZ7tz_61D6m6x6QOgAmZK00x3H1s2beHNUZolh2yelvqYX6-wjjST4uElQuqUg-WeIni30/s1600/p5.PNG&quot; height=&quot;437&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;strong&gt;Step 7&lt;/strong&gt;. Click back on the targeting setting in the top pane and press “F8” which changes the option to “does not exist” then click OK and OK.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6B5VQWE90F31GopApC8UtzOarYkDxw6QHetIp2aiZ5Bbqw_UyNhn45FzBymM2md8mk91oEKNSwpEklV4SdCvkIDEGcSjNzQFzzZpqLRsp9ZwEO1QWyuuQXsea3maem24xuak441j8C-4/s1600/p6.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6B5VQWE90F31GopApC8UtzOarYkDxw6QHetIp2aiZ5Bbqw_UyNhn45FzBymM2md8mk91oEKNSwpEklV4SdCvkIDEGcSjNzQFzzZpqLRsp9ZwEO1QWyuuQXsea3maem24xuak441j8C-4/s1600/p6.PNG&quot; height=&quot;435&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
This policy will now apply the blank screen saver on the next group policy refresh to all targeted users whenever they select the “(None)”.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWGspiLIAFRCdxied_ahKl_N5bJ13DFLgrqnkv_Fn6xvhbobXprhaz05ayDz2I3X65ZnQ-b3SCxFUlvm0hb4w6dhCWxxoNHGCbo5b8uigw7wXrWdnx_IvVnM8C5p7YgjMFeWcg6c_m1A0/s1600/p7.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWGspiLIAFRCdxied_ahKl_N5bJ13DFLgrqnkv_Fn6xvhbobXprhaz05ayDz2I3X65ZnQ-b3SCxFUlvm0hb4w6dhCWxxoNHGCbo5b8uigw7wXrWdnx_IvVnM8C5p7YgjMFeWcg6c_m1A0/s1600/p7.PNG&quot; height=&quot;291&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/7633232674861213946/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2014/07/how-to-use-group-policy-to-allow-users.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/7633232674861213946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/7633232674861213946'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2014/07/how-to-use-group-policy-to-allow-users.html' title='How to use Group Policy to allow the users to chose any screensaver except (None)'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjeoGgYvidxMNjSgnOq_aPHXfS8ZEaW2a5DO4GRMHxi8gJaqTNPs7Jjaj9ly2XYM4mPFjckReCqdBjOrG5l11z5vZv1fuU5w_klNklewHVWiO0ZyvxIStEP6VB75coTgM1Cgrhd9z5Ugtk/s72-c/p1.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-6750438578182373662</id><published>2014-07-19T01:18:00.000-05:00</published><updated>2014-07-19T01:18:10.902-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Exchange"/><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><title type='text'>Installing Exchange Server 2010 SP3 Rollup 6</title><content type='html'>To get the permissions correct for installing Rollups on Exchange 2010 SP3, you will need to either disable UAC (not recommended) or you will need to launch the Rollup installer from an elevated command prompt (Right click and Run as Administrator) with the following command:&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New, Courier, monospace;&quot;&gt;msiexec /update Exchange2010-KB2936871-x64-en.msp&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
This will allow the rollup to install properly. Other words, it will Roll Back and say that it Ended Prematurely.&lt;br /&gt;
&lt;br /&gt;
Another note on Rollup 6 for SP3 is that it takes (at least in my environment) an extremely long time to generate native images for .NET assemblies. One of my servers took 45 minutes for this process. Wait it out and you&#39;ll be able to get it installed, just plan your windows accordingly.&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/6750438578182373662/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2014/07/installing-exchange-server-2010-sp3.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/6750438578182373662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/6750438578182373662'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2014/07/installing-exchange-server-2010-sp3.html' title='Installing Exchange Server 2010 SP3 Rollup 6'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-8241070769380919645</id><published>2014-05-15T08:21:00.000-05:00</published><updated>2014-05-15T08:21:52.326-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="2008r2"/><category scheme="http://www.blogger.com/atom/ns#" term="Error"/><category scheme="http://www.blogger.com/atom/ns#" term="ESXi"/><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft"/><category scheme="http://www.blogger.com/atom/ns#" term="vCenter"/><category scheme="http://www.blogger.com/atom/ns#" term="VMware"/><category scheme="http://www.blogger.com/atom/ns#" term="VMware Tools"/><category scheme="http://www.blogger.com/atom/ns#" term="Windows Server"/><title type='text'>The wizard was interrupted before VMware Tools could be completely installed.</title><content type='html'>Upon attempting to install VMware Tools on a Windows Server 2008R2 server, I received an error stating &quot;The wizard was interrupted before VMware Tools could be completely installed.&quot;&lt;br /&gt;
&lt;br /&gt;
After looking around on the internet, the closest thing I could find was &lt;a href=&quot;http://david-homer.blogspot.com/2014/01/the-wizard-was-interrupted-before.html&quot; target=&quot;_blank&quot;&gt;this post by David Homer&lt;/a&gt;, detailing a similar issue with VMware Tools on VMware Workstation.&lt;br /&gt;
&lt;br /&gt;
I tried his fixes (remove VMware Tools registry key, remove the vmtools service), but none of them allowed me to get past the problem.&lt;br /&gt;
&lt;br /&gt;
What eventually worked was doing a search in the registry for all references to &quot;vmware&quot; and removing all keys having to do with VMware Tools - make sure you don&#39;t remove any of the keys referring to your SCSI devices/other hardware; just the VMware Tools entries.&lt;br /&gt;
&lt;br /&gt;
I believe it was most likely the Installer registry entries that were mucking it up.&lt;br /&gt;
&lt;br /&gt;
After a quick reboot to refresh the registry, VMware Tools installed with no issues.&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/8241070769380919645/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2014/05/the-wizard-was-interrupted-before.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/8241070769380919645'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/8241070769380919645'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2014/05/the-wizard-was-interrupted-before.html' title='The wizard was interrupted before VMware Tools could be completely installed.'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-4451755992299411311</id><published>2014-04-30T07:09:00.000-05:00</published><updated>2014-04-30T07:09:24.626-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Error"/><category scheme="http://www.blogger.com/atom/ns#" term="Graylog2"/><category scheme="http://www.blogger.com/atom/ns#" term="Monitoring"/><category scheme="http://www.blogger.com/atom/ns#" term="syslog"/><title type='text'>Graylog2 Version Check Errors</title><content type='html'>I noticed periodic warnings in my Graylog2 0.20.1 instance saying:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;WARN : org.graylog2.periodical.VersionCheckThread - Could not perform version check&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
The fix for this (as detailed &lt;a href=&quot;https://www.mail-archive.com/graylog2@googlegroups.com/msg00644.html&quot; target=&quot;_blank&quot;&gt;here in Google Groups by Lennart Koopmann&lt;/a&gt;) is to set an undocumented flag in your&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt; /etc/graylog2.conf&lt;/span&gt; as follows:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;versionchecks = false&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/4451755992299411311/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2014/04/graylog2-version-check-errors.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/4451755992299411311'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/4451755992299411311'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2014/04/graylog2-version-check-errors.html' title='Graylog2 Version Check Errors'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-9167819820880381770</id><published>2014-04-29T14:00:00.000-05:00</published><updated>2015-05-06T08:47:58.053-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="FortiGate"/><category scheme="http://www.blogger.com/atom/ns#" term="FortiNet"/><category scheme="http://www.blogger.com/atom/ns#" term="Graylog2"/><category scheme="http://www.blogger.com/atom/ns#" term="Monitoring"/><category scheme="http://www.blogger.com/atom/ns#" term="syslog"/><title type='text'>Graylog2 Extractors for FortiGate </title><content type='html'>UPDATE: I&#39;ve created the JSON version of this for Graylog 1.0 in &lt;a href=&quot;http://www.virtualizetheworld.com/2015/05/fortigate-extractors-for-graylog-10.html&quot; target=&quot;_blank&quot;&gt;a new post here.&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Graylog2 is a really powerful log monitor, but it needs some customization when it comes to specific devices.&lt;br /&gt;
&lt;br /&gt;
Pointing a Fortinet FortiGate firewall to Graylog2 results in mediocre usage, due to the syslog field not getting extracted properly. Essentially you end up with all of the data just dumped into the message field.&lt;br /&gt;
&lt;br /&gt;
To point the FortiGate to Graylog2, open the FortiGate console and config the syslog settings:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;config log syslogd setting&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Then enable and point the logging to your server:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;set status enable&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;set server 192.168.40.50&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;set port 514&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;set facility syslog&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Once Graylog2 is successfully receiving the logs from the FortiGate, you will need to use extractors for custom processing of the specific syslog messages using the Drools Rule File in Graylog2. You can read more in Graylog2&#39;s help file &lt;a href=&quot;http://support.torch.sh/help/kb/graylog2-server/custom-message-rewritingprocessing&quot; target=&quot;_blank&quot;&gt;&quot;Custom message rewriting/processing.&quot;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
To implement the drl file, edit your &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;graylog2.conf&lt;/span&gt; file and uncomment the following line, making sure that it points to your drl file:&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;rules_file = /etc/graylog2.drl&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Then create your drl file with the rules that you need. Below are the extractors that I use for FortiGate. These are most of the fields that I&#39;ve run across in the messages that seemed to be of value to me. If there are others, then follow the template and add them. Please notice that some of the fields (like &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;action&lt;/span&gt;) don&#39;t have quotes around the variable, but others (like &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;app&lt;/span&gt;) do, and there are different patterns to match them. There are also a couple of exceptionones (service, status, and vd) that sometimes have quotes and sometimes don&#39;t have quotes, so I&#39;ve got rules in there to take both into account.&lt;br /&gt;
&lt;br /&gt;
The only one that I can&#39;t seem to get working correctly is msg one that is supposed to replace the &quot;message&quot; field with the contents of &quot;msg.&quot; I&#39;ll update here if I can get it working. &lt;br /&gt;
&lt;br /&gt;
To implement the drl file, restart your graylog2-server service, and watch the logfile to make sure that there are no errors on start up.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;# Graylog2 Extractors&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;import org.graylog2.plugin.Message&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;import java.util.regex.Matcher&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;import java.util.regex.Pattern&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;import java.text.DateFormat&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;import java.text.ParseException&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;# Fortigate&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;rule &quot;Fortigate source rewrite&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp; when&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; m : Message ( message matches &quot;.+devname=.+\\sdevid=.+&quot; )&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp; then&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher matcher = Pattern.compile(&quot;^.+\\sdevname=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (matcher.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;source&quot;, matcher.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher action = Pattern.compile(&quot;^.+\\saction=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (action.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;action&quot;, action.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher app = Pattern.compile(&quot;^.+\\sapp=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (app.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;app&quot;, app.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher appact = Pattern.compile(&quot;^.+\\sappact=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (appact.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;appact&quot;, appact.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher appcat = Pattern.compile(&quot;^.+\\sappcat=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (appcat.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;appcat&quot;, appcat.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher applist = Pattern.compile(&quot;^.+\\sapplist=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (applist.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;applist&quot;, applist.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher attack = Pattern.compile(&quot;^.+\\sattack=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (attack.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;attack&quot;, attack.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher devid = Pattern.compile(&quot;^.+\\sdevid=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (devid.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;devid&quot;, devid.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher dir = Pattern.compile(&quot;^.+\\sdir=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (dir.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;dir&quot;, dir.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher dstcountry = Pattern.compile(&quot;^.+\\sdstcountry=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (dstcountry.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;dstcountry&quot;, dstcountry.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher dstintf = Pattern.compile(&quot;^.+\\sdstintf=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (dstintf.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;dstintf&quot;, dstintf.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher dstip = Pattern.compile(&quot;^.+\\sdstip=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (dstip.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;dstip&quot;, dstip.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher dtype = Pattern.compile(&quot;^.+\\sdtype=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (dtype.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;dtype&quot;, dtype.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher duration = Pattern.compile(&quot;^.+\\sduration=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (duration.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;duration&quot;, duration.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher error_reason = Pattern.compile(&quot;^.+\\serror_reason=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (error_reason.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;error_reason&quot;, error_reason.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher eventtype = Pattern.compile(&quot;^.+\\seventtype=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (eventtype.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;eventtype&quot;, eventtype.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher file = Pattern.compile(&quot;^.+\\sfile=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (file.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;file&quot;, file.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher group = Pattern.compile(&quot;^.+\\sgroup=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (group.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;group&quot;, group.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher hostname = Pattern.compile(&quot;^.+\\shostname=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (hostname.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;hostname&quot;, hostname.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher identidx = Pattern.compile(&quot;^.+\\sidentidx=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (identidx.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;identidx&quot;, identidx.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher init = Pattern.compile(&quot;^.+\\sinit=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (init.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;init&quot;, init.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher locip = Pattern.compile(&quot;^.+\\slocip=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (locip.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;locip&quot;, locip.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher locport = Pattern.compile(&quot;^.+\\slocport=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (locport.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;locport&quot;, locport.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher logid = Pattern.compile(&quot;^.+\\slogid=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (logid.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;logid&quot;, logid.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher mode = Pattern.compile(&quot;^.+\\smode=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (mode.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;mode&quot;, mode.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher msg = Pattern.compile(&quot;^.+\\smsg=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (msg.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;message&quot;, msg.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher outintf = Pattern.compile(&quot;^.+\\soutintf=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (outintf.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;outintf&quot;, outintf.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher peer_notif = Pattern.compile(&quot;^.+\\speer_notif=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (peer_notif.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;peer_notif&quot;, peer_notif.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher policyid = Pattern.compile(&quot;^.+\\spolicyid=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (policyid.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;policyid&quot;, policyid.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher profile = Pattern.compile(&quot;^.+\\sprofile=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (profile.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;profile&quot;, profile.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher profiletype = Pattern.compile(&quot;^.+\\sprofiletype=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (profiletype.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;profiletype&quot;, profiletype.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher proto = Pattern.compile(&quot;^.+\\sproto=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (proto.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;proto&quot;, proto.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher quarskip = Pattern.compile(&quot;^.+\\squarskip=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (quarskip.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;quarskip&quot;, quarskip.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher rcvdbyte = Pattern.compile(&quot;^.+\\srcvdbyte=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (rcvdbyte.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;rcvdbyte&quot;, rcvdbyte.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher rcvdpkt = Pattern.compile(&quot;^.+\\srcvdpkt=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (rcvdpkt.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;rcvdpkt&quot;, rcvdpkt.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher ref = Pattern.compile(&quot;^.+\\sref=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (ref.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;ref&quot;, ref.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher remip = Pattern.compile(&quot;^.+\\sremip=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (remip.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;remip&quot;, remip.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher remport = Pattern.compile(&quot;^.+\\sremport=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (remport.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;remport&quot;, remport.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher result = Pattern.compile(&quot;^.+\\sresult=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (result.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;result&quot;, result.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher role = Pattern.compile(&quot;^.+\\srole=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (role.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;role&quot;, role.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher sentbyte = Pattern.compile(&quot;^.+\\ssentbyte=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (sentbyte.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;sentbyte&quot;, sentbyte.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher sentpkt = Pattern.compile(&quot;^.+\\ssentpkt=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (sentpkt.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;sentpkt&quot;, sentpkt.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher service = Pattern.compile(&quot;^.+\\sservice=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (service.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;service&quot;, service.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; } else {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher servicenq = Pattern.compile(&quot;^.+\\sservice=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (servicenq.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;service&quot;, servicenq.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher srccountry = Pattern.compile(&quot;^.+\\ssrccountry=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (srccountry.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;srccountry&quot;, srccountry.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher srcintf = Pattern.compile(&quot;^.+\\ssrcintf=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (srcintf.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;srcintf&quot;, srcintf.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher srcip = Pattern.compile(&quot;^.+\\ssrcip=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (srcip.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;srcip&quot;, srcip.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher srcport = Pattern.compile(&quot;^.+\\ssrcport=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (srcport.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;srcport&quot;, srcport.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher stage = Pattern.compile(&quot;^.+\\sstage=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (stage.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;stage&quot;, stage.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher status = Pattern.compile(&quot;^.+\\sstatus=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (status.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;status&quot;, status.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; } else {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher statusnq = Pattern.compile(&quot;^.+\\sstatus=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (statusnq.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;status&quot;, statusnq.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher subtype = Pattern.compile(&quot;^.+\\ssubtype=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (subtype.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;subtype&quot;, subtype.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher transport = Pattern.compile(&quot;^.+\\stransport=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (transport.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;transport&quot;, transport.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher type = Pattern.compile(&quot;^.+\\stype=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (type.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;type&quot;, type.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher trandisp = Pattern.compile(&quot;^.+\\strandisp=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (trandisp.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;trandisp&quot;, trandisp.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher transip = Pattern.compile(&quot;^.+\\stransip=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (transip.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;transip&quot;, transip.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher user = Pattern.compile(&quot;^.+\\suser=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (user.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;user&quot;, user.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher utmaction = Pattern.compile(&quot;^.+\\sutmaction=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (utmaction.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;utmaction&quot;, utmaction.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher utmevent = Pattern.compile(&quot;^.+\\sutmevent=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (utmevent.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;utmevent&quot;, utmevent.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher vd = Pattern.compile(&quot;^.+\\svd=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (vd.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;vd&quot;, vd.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; } else {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher vdnq = Pattern.compile(&quot;^.+\\svd=(\\S+)\\s&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (vdnq.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;vd&quot;, vdnq.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher virus = Pattern.compile(&quot;^.+\\svirus=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (virus.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;virus&quot;, virus.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher vpntunnel = Pattern.compile(&quot;^.+\\svpntunnel=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (vpntunnel.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;vpntunnel&quot;, vpntunnel.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher xauthgroup = Pattern.compile(&quot;^.+\\sxauthgroup=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (xauthgroup.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;xauthgroup&quot;, xauthgroup.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Matcher xauthuser = Pattern.compile(&quot;^.+\\sxauthuser=\&quot;(\\S+)\&quot;&quot;).matcher(m.getMessage());&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if (xauthuser.find()) {&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; m.addField(&quot;xauthuser&quot;, xauthuser.group(1));&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;nbsp; end&lt;/span&gt;&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/9167819820880381770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2014/04/graylog2-extractors-for-fortigate.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/9167819820880381770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/9167819820880381770'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2014/04/graylog2-extractors-for-fortigate.html' title='Graylog2 Extractors for FortiGate '/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-5428951175613368182</id><published>2014-04-23T16:01:00.003-05:00</published><updated>2014-06-25T14:35:07.104-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CentOS"/><category scheme="http://www.blogger.com/atom/ns#" term="ElasticSearch"/><category scheme="http://www.blogger.com/atom/ns#" term="Graylog2"/><category scheme="http://www.blogger.com/atom/ns#" term="Monitoring"/><title type='text'>Install ElasticSearch 0.90.10 on CentOS 6</title><content type='html'>Graylog2 0.20.x requires ElasticSearch 0.90.10. To fullfil this requirement, you will need to manually download and install the RPM for ElasticSearch.&lt;br /&gt;
&lt;br /&gt;
Download ElasticSearch 0.90.10 from &lt;a href=&quot;http://www.elasticsearch.org/downloads/&quot; target=&quot;_blank&quot;&gt;the ElasticSearch Downloads page here.&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Save the file and upload it to your CentOS 6 server.&lt;br /&gt;
&lt;br /&gt;
Install Java 1.7:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#yum install java-1.7.0-openjdk.x86_64&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Install the RPM:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#rpm -ivh elasticsearch-0.90.10.noarch.rpm&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Stop the elasticsearch service so that we can update the cluster name:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#service elasticsearch stop&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Edit the &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;/etc/elasticsearch/elasticsearch.yml&lt;/span&gt; file to update your &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;cluster.name&lt;/span&gt; variable. Ex:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;cluster.name: graylog2_production&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Update any additional settings needed and save the file. I recommend updating the &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;path.data&lt;/span&gt; and &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;path.logs&lt;/span&gt; to custom directories.&lt;br /&gt;
&lt;br /&gt;
Start the elasticsearch service and set it to run on startup:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#service elasticsearch start&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#chkconfig elasticsearch on&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Check your logs to make sure that it started properly and joined the cluster (if there is an existing one).&lt;br /&gt;
&lt;br /&gt;
For Graylog2, the recommended settings are also to increase the open file limit to at least 64000 as seen in the &lt;a href=&quot;http://support.torch.sh/help/kb/graylog2-server/configuring-and-tuning-elasticsearch-for-graylog2-v0200&quot; target=&quot;_blank&quot;&gt;Configuring and tuning ElasticSearch for Graylog2 &amp;gt;v0.20.0&lt;/a&gt; documentation. I did this by increasing the max number of ulimit open file below.&lt;br /&gt;
&lt;br /&gt;
Edit &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;/etc/sysctl.conf&lt;/span&gt; and add the following line at the end:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;fs.file-max = 65536&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Save the file. Next edit &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;/etc/security/limits.conf&lt;/span&gt; and add the following lines:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; soft&amp;nbsp;&amp;nbsp;&amp;nbsp; nproc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65535&lt;br /&gt;*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hard&amp;nbsp;&amp;nbsp;&amp;nbsp; nproc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65535&lt;br /&gt;*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; soft&amp;nbsp;&amp;nbsp;&amp;nbsp; nofile&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65535&lt;br /&gt;*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hard&amp;nbsp;&amp;nbsp;&amp;nbsp; nofile&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65535&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Save the file and restart the server.&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;#shutdown -r now&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Once restarted, verify that the max open file ulimit has been increased.&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;# ulimit -a&lt;br /&gt;core file size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (blocks, -c) 0&lt;br /&gt;data seg size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (kbytes, -d) unlimited&lt;br /&gt;scheduling priority&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-e) 0&lt;br /&gt;file size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (blocks, -f) unlimited&lt;br /&gt;pending signals&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-i) 30507&lt;br /&gt;max locked memory&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (kbytes, -l) 64&lt;br /&gt;max memory size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (kbytes, -m) unlimited&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;open files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-n) 65535&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;pipe size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (512 bytes, -p) 8&lt;br /&gt;POSIX message queues&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (bytes, -q) 819200&lt;br /&gt;real-time priority&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-r) 0&lt;br /&gt;stack size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (kbytes, -s) 10240&lt;br /&gt;cpu time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (seconds, -t) unlimited&lt;br /&gt;max user processes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-u) 65535&lt;br /&gt;virtual memory&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (kbytes, -v) unlimited&lt;br /&gt;file locks&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (-x) unlimited&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Additional recommended settings are to increase the &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;ES_HEAP_SIZE&lt;/span&gt;. I did this by editing &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;/etc/init.d/elasticsearch&lt;/span&gt; and adding the following line after &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;checkJava&lt;/span&gt; under &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;start()&lt;/span&gt;:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;ES_HEAP_SIZE=2g&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
They recommend that you leave 50% of your memory for other system functions, and I had 4 Gig of RAM, hence the 2g setting.&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/5428951175613368182/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2014/04/install-elasticsearch-09010-on-centos-6.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/5428951175613368182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/5428951175613368182'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2014/04/install-elasticsearch-09010-on-centos-6.html' title='Install ElasticSearch 0.90.10 on CentOS 6'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-8697359581395168322</id><published>2014-04-23T14:50:00.001-05:00</published><updated>2014-04-23T14:52:52.567-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CentOS"/><category scheme="http://www.blogger.com/atom/ns#" term="Monitoring"/><category scheme="http://www.blogger.com/atom/ns#" term="RedHat"/><title type='text'>Ship RHEL 6 or CentOS6 syslogs</title><content type='html'>Reference more for myself than for y&#39;all, but you get the shared benefit.&lt;br /&gt;
&lt;br /&gt;
To ship the logs from RHEL6 or Centos 6 to a remote syslog server, edit the following file: /etc/rsyslog.conf&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
At the bottom of the file, remove the comment from the remote-host entry, and update with your server name or IP. Example:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;*.* @@192.168.40.15:514&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Restart the rsyslog service:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;service rsyslog restart&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Make sure you are receiving the logs at your syslog server.&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/8697359581395168322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2014/04/ship-rhel-6-or-centos6-syslogs.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/8697359581395168322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/8697359581395168322'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2014/04/ship-rhel-6-or-centos6-syslogs.html' title='Ship RHEL 6 or CentOS6 syslogs'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-398974078253067653</id><published>2014-04-23T13:31:00.002-05:00</published><updated>2015-02-18T08:44:50.833-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CentOS"/><category scheme="http://www.blogger.com/atom/ns#" term="ESX"/><category scheme="http://www.blogger.com/atom/ns#" term="ESXi"/><category scheme="http://www.blogger.com/atom/ns#" term="RedHat"/><category scheme="http://www.blogger.com/atom/ns#" term="vCenter"/><category scheme="http://www.blogger.com/atom/ns#" term="VMware"/><title type='text'>Install VMware Tools on RHEL 6 or CentOS 6</title><content type='html'>&lt;br /&gt;
Below is the process to install VMware Tools on RHEL 6 or CentOS 6. This guide is more here for me than anyone else, but I hope that you can benefit from it.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Install the Pre-Requisites:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;yum install make gcc kernel-devel kernel-headers glibc-headers perl&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Start the VMware Tools installation process on your VM:&lt;br /&gt;
&lt;img src=&quot;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAgUAAACBCAYAAABQIsnqAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAACK6SURBVHhe7d1/cFTl/S/wdxb5IZe2337nW1rQVkogTGO+OGPs1GC+KF5Hg7GClqZKR8MwJKS9l0iwMBddrzpk5DtQTVi/fwRiuTBYtKn2IrKyWhW10agV78AsuSUQRK8a9TvjiAJJIMB9Ps95ztmzu+dsNiGB3eX9ch72/D67a3afz/N5nrMn78VI5MwZnEEStci9/IzayuFeFzetpsx2+l/XOlmeZx6T152WXc20mZC1ZkP9aO9nTcq/elpz1ql/zWK9xMy6j6kX6Clr2l6juc7hSFpm5lwLPfayqMWea8zz8dlrgLxPEluU4iyDfAJp7aY3GtgJBru18zdn/3/2OFDsb8Bf/BY+2/d/GF/97uqzQZ764OQF8hAIBNR0HkZedBHGjBmF0aNHYsxoeRyFUaNGYrQqo0aNwkUjRpg9DbWP7BtQj3nOo1qWp6bVoxxTPpuynfUo/wylFAc0q2JbeG+rl8b+SZK8ysyoB2sqbqWml6jX7MdaryddEhb47B5b7LMB0TmU/l+h+g747nf/6Sy+5ohouEm95a7UR41UQYEKBMaMGa2DA5kepQKE0SogkAAhVVBgBxZ6XhcrKLA2i38kogtP3ldffcWggIiIiBAwj0RERHSBS5kpaGxsNFPnztKlS80UERERnUv9BgXBYNDMDb/6+noGBUREROcJuw+IiIhIY1BAREREWr9BgVzffa4KERERnT8DzhREfjMSM0MHzZwR+Q1G/iYiE/jNyJFmOtnB0EyMHDkTibsTERHR+TfgoKBsziK0/d/4Wj3y3BNYNKfMzJWgZN8jHhV/BI/e22amiYiIKNMMfEzBlJ+g5InnVBVvi+C5JxbBiQmUyy8HnnkhMZvwHJ5YtAiLzCwRERFllsCNS/9qJtM05WbMK3kCz9lRga7s58AVE+An996Hy+991BU4HETokX149N45Zp6IiIgyTQDT8s2kt+QBgfmYPa8E+zoO6Pmd0nVw603Oemunm3DrIhU47DT7HHgBz2AeZufb6+1jxRciIiI6fwK33TTZTKZvyux5wDM7Vfv/IA7sK8FPppgVLmXLHsW+1Y+rLYDIY/fi8pVL4LEZERERZYjAIGICiQpUu/8Z7IzstDIAXrW9s83jWL3vUSxz9y8QERFRxgkMJiZQNT4kWXDvrfcC82b7ZACmYMnKy/vZhoiIiDLFoH/RULoQStR/8zzTBEbZMjxasggrlzAkICIiynT93hBp5cqVZm74rV69mjdEIiIiOk8GnSkgIiKi3MKggIiIiDQGBURERKQxKCAiIiKt34GGDzzwgJkbfqtWrTJTRJQtODiYKHdkVFBARNlFAnkGBUS5o9/uA7knwenTp51y6tQpp/T19Tnl5MmTTjlx4gR6e3t16enp0aW7uxvHjx/X5dixYzh69KguRERElBk4poCIiIg0BgVERESkMSggorMi3YDSRShdh9LFyNugE2UvBgVEdFY+++wzfPnllzowkLFGRJS9GBQQ0Vnp7OzEJ598gm+++UYPOmamgCh7ZVlQEEHNiBEY4ZRShDrNKiI6Lz7//HOdKZAri5gpIMpuWZgpKEFDh3VJZEcDUFcZAuMCosGTAPtsSDAglx/bWQJmCoiyV1Z3H+TXBlHV1oIwowKis3I2gQEHFxLljtwaU9AZQqmre6EmYi2O1MSmrS4IV7eD7GOvjNu/Rm0prO1rakpdy4hyz9lmDIgo+2V1UNAZqkdzSQXK82VOVd4FdSgKm19c7GhAtNyq/MvmVqF5mx0hbEO0BGgx6YXOcAtQOFVWqP1bUGG6Jk6FgXoncmhDtHCzWt6EMrOEKBcxMCC6sGVhUNCGugKrNV9QV4Rway10TNDZgSiqMNeutfNrEaxqQ/sBNT21ECXRDj32ILItiopghUQFar4TEhNUSFSh948de0R5M9r0zqLE2oYox3GgINGFLasHGqbdcs8vRwVk7EEE26IVKC+T+XYc6AyrpXamQVQhrI9rShPzAnThYEBARLkzpiC/AEVoht1LIOMD6pvtzEE+yiU5UFmPaEW5mpP5KLatbZc0gZVpMPvHugyILhwMCIhI5NBAwzI06XEEJv2vxwfEMgn5EhW0ma4CMx9tjrq6Baz9UVdg7S8lNjqRKGcxICAiW95XX33ley1RY2MjgsFg3OVG6U7b8+5Hr+lx48bpRyLKPqtWrcKoUaNwySWXYNq0afpx7NixOqgmouyTQ5kCIiIiOhsMCoiIiEhjUEBEREQagwIiIiLS0hpo+LM/cNAQEcV7d9FpPdCQiDLb0qVLzVT/0g4K1vF3fIjIuCcSCwoeeOABs5SIMo18RgcSFLD7gIjOilxeLHdKtIvzi6CqyO2U7XLy5EmnnDhxQt9uWUpPT48u3d3d+jbMUo4dO4ajR4/qQkTnDoMCIiIi0hgUEBERkcaggIiIKIdJN5x00UnXnXTx2b8o7CU7g4LD61BzWR5K7XL7OnxsVhEREVHMZ599hi+//FIHBv3d6yT7ggIJCK5twfWvn0Hrh1b5/bT2IQ4KdmLNZdeg5bCZJcphElgTUe7q7OzEJ598gm+++UYP+s2hTMFBtCxbismb3kTFJLNIuXr1elxtpolo4HIxMNi7ZSmWbtlr5jLU3i36cjG7rHn5C7NiGH3xMtYsXYNzcSrKDJ9//rnOFMiVPbmVKTgcxqu7qzFzlplPktjCT5iP63ZYjLf1QhVo3B7rilizS/a5GdvxFkLXqmUrd+qtiHJdTgUGquKLdBWjuCuSuZWfBAQbu3DLfY36N2EaG+/Dle8/MgyBwV5scQcB42/AisYVuGG8maecJ8GAXP5rZwlSZgq2bdsGv5KRigtxqZn8eOM1pjJPJ9WvKnt3t8MmYNPGg8CutQhNe8HpilgxazZWfPgCbsUM1Mq2q2eb/YlyX64EBl/sfR+48ibcdCXw/t5MjAq+wMuR3She6K6cx+OGBbcAO15U1TjR0NmzZw/eeecdvPLKK9ixYweee+45zzpfSqCyshJ+JSPtjo0fuHThm6oilwo8DYc7cMhu/UsgsWADogcOAD8uRNHWm1EjAQLRBU4C4+z3BXRMMH08xk/XUYFaYjOt5pdjaftYy1xV1GtiqXzpeZAuiFgPREKLW9Lw9kqdkrf33WIqdWv7LVvWuJYZX+zF+58W44rpZt42fjqunNiFL/Q5Es7ndf6kcya+BtlnI3bjU+x4RC3TzzfVcTxer+d7Rdnkpz/9Ka677jrMmTMH8+fPx9133+1Z50sJHDlyBH4l40wqwGRE8dGgBwBW4/cmI6CLZAEm3YMmNR1EpQ4W1uwymxJdYHIjIFCkwsWVUDGBVcmqufhkgaogu66wUvYLi/Gp3TLf+yJ2TFhoUvmNuEtV2NOvKMbuPaaW3LsHXRNjmQedjZjwA1mBLY+oM9rdAAuBiFN5foquCQvU8ruQWP9j4gTI3snUPp+ZSV8+50x6DdNxl1pZjIlWN4W8qDhynB2YsNAc575b0LXRHYj4vFeUVeSqA+lCkEsTv/76a8/63i6B73znO/ArmWc25j8I1dq3xwMkmopJxW/h8Admdtc2bDeTVkCxweoy8CBZh6cfnIFDHzBjQBeenAkIFKvrYDqsrPx4SLJgx4vuqkxVkDeZynH6FarCNC3zH0zAxN0b41vDsqzrC51p2LunC1eW2ZmHWDZCdu6yW+LSot6o2uVOrT7R2sbLp13wrvsnWrFGKn7n9HoNqejjuDIW429AWbE7KPF5ryirjBkzBmPHjsW4cePw7W9/27O+t0sgLy8PfiUT6S6DTcDv9FgCKTfj0IObzdUIU1CxpBrbF5h1L8HVtTAbK15vBB6eavZTRQYR7lrszN/xcBEWLJyit505nwMN6cKQSwGBtHxf3PGpatE+4qS8H1HzqrnffwtXD8BrxAJs0vvpNLqTadiLPV1XYrpqeV+pKsbP3NkIrRgLTetcl6QWeQLdTbAbdhLCobsVJmC8TxwRz+OcXq+BLnjLli3DL3/5SxQVFemK/6KLLvKs86Vk548XzVof6wJQpUlX5IZ73er1WPGh6/JF01UQWz874VixSxuvXu3ahoiyw9492D3xFtznriwb78MtXhWwj/E3rMB9t0xEl24SW5mG9zdF0KWzDzLfhT0vdsWyEaoGn4Ddri6DdIzHDWXF2L3RPdbASuWrprnpavgBJkx0tdrltZnJ/s4Z/xpSMMdx3hu5amO3x1iHJGa8gT683zRlo+wMCoiIPOzdsxsTna4Dm1TkE2NjA/y4fjPgkR0TUGYuC9CDFT81XQVmvmt3l6tbYDruuk+uGohlJ9L6fYTpd+mxABvtfZZuRNct92GFczmCHTiY9XskN2DzOafna5iOK4rdAw3drON02efQ4xQ8xj/QBUP6CHxzhw899BCCwSB+9ocRWFdmFhLRBe+eCPDuotP6Xu3yHeG+7jndaXve/eg1Lf2guU9a2BuBhdYAR6KhIp9RqcvTxUwBEdF5Z10lANNiT3ugINEQSztTQETkxkwBUeYbaKYgraDA/nCKdKftefej1zQ/8ETZi0EBUWZj9wERERENCoMCIiIi0hgUEBERkcaggIiIiDQGBURERKRlX1AQqcGIESNMqUHELB5+EdSMKEWo08wSERHlmOwKCjpDKC0HwqdO4ZSUjkJ0nLuoYJAYTFBmkwCbiEhkV1BwoB1tJYWYamaRX4ta/vwy0VnLqcBg2LKJ/QX4nQiV2udVpTSklqRjcA2HSI06R03iqxvKRkg6x2KjJ9dkV1BQNhdVbXWoTPoLNH+YodiXQalrG/3hsT+ozofI7BMJoTRpn/gPd9zn7oDX9opkMczy2D5yjnI0ow11BWp50geYKHPI323WO1/ZRP35L0B70JxXymb1PJzvgSGuONX56qNVqIrWpzguK2waOCcokPsr2+SeypmpDE2nOlDRUpBcWUvF2z7X+jCGq9BWt1Z9JCxlTfYHNYyqZveHSO1TD2zWXx4NQF2ltS6yFnVFYefD3eRkI1zbx51DffgK6lAUNudRx4qWy4dRnq86J0rQ0KGWxw5ElJGyPjA4L9lE1YiotD7/cR/xYTx3Z7gFqFiO5RVAS5i1Pg2dgAQAUvr6+nRgINPuACHz5KO21a543YGBqniXm0+gZBQQRYf9WXHSidJqd1P7bK5VR1TUBzhY1Yb2A2p6aiFKmsvjMwGaa3v3OTo71FQV5tpfAO5jEWURCWqzmm82UYnL5tndCqY17ZNldO9TGuowCxN0htHS5vr8x/HKFlrnrKkpdT2PRJKt9F+nY4LyfOSX66jAo5vC67y2FMdO9Xo93z/KNQH5ffFAIKADAQkM3L85ntFUxbu5oQTN2/r505Q/ZCed2AG1i49OdETNpDp2q9p+Myr1B4BZf7oQZH1AoPllEyWb14IKydjJd0EYqHcqf78so+wTywBuRktCo8LFnZ2I45ctbEO0cLM6bpPaYoAkCEEFVEygvqvK1VQLkpMFg8lSpnq9qd4/yiW6+0D+J0tAoBeoAMHOGmScSMiV+pdouU19Fr0/ig53OlFH9Hqp0RZLvXlE+/m1rehQUUTUSTn4yC9Akfr4OPGJCkTqm/1aDkSZR74DcodHNlFn80yrWVq65aoN7aTyfLKMsk9JA+xV+bVBtc5HWzsGlhgs0S39JE5rvAB1bc0o19PxDROr66DcyliqfyVZULfWtYGf/o6d6vWmfP8ol+igQP4nCwkETp8+raczUlkB2u0/SvnDLgqjtdbjg+VWthwNqEOB7FPZjqK4TEEJitqtbMAIHSGbqN01ermgrgjB/s4hUbn5ArKOJRG13QIow9wqrxQeUWbIrYDAJSmbWBUbgChlqMb4SGu9xNUoOBsmS2llNWPPN/ZUI1hb14a2OisTYn1HqZZO8zaT3Uih32P3Z5jeP8oogZaWFmzdulVnCJ5++mk8+eST2L59u5M5yCySEvP6o5TlrYjV3e5502qQ7Vub0NTq3g4oXN7qHC92uKbYOZz0XqpzKM4HTkr8OZyBjvwQEQ0vv2yiyeYNKOUt+7TVwW6Ed4bqfboP1HdMsArNcWOcFNUyDw1FoOAW2YZm1ZrvcL5rpEglPwRBSarXO5j3j7JS4I477tDR5p/+9CecPHkSlZWV+Oabb3SAQESUVXyziSqI11cYxVrY/Wfu1D5hq7KX7StR4d99IA0Jd7ZQSiVQrtsBg8kWSmMmebxBZFszSpyuA5t0IXiNr/I7r/exU7/ewbx/lI3k2sMzki2QiHP+/Pm6C+GPf/yjnt+/fz+CwWDcwMN0p+1596PX9Lhx4/TjuSejc+tR2BHfqiei9K1atSqHvyOIsp98Rh966CEz1z9noOGoUaP0h1CyBZI9uPPOO/UGuSsh/U9ERHSB00HByJEjnahcZPRgQyIiIhoWARlgKJkCOygYM2aMfszsHzAiIiKioRaQAYV2/92WLVvQ09NjVhEREdGFJPCrX/1KjyGQsnjxYr1QRpZm5iWJRERENFz01QcypkAGGArpPrCzBTJi8XyPLH7ttdfMFBFlkuuuu45XHxBluIFefZCnnLEzA+7gQKbvv/9+fuCJyBeDAqLMNqigQD58F198Mbq7u/UvG8qdEmXwYSZkCogoc2VCUMBsIpE3O5s3oKBAFeeTKgGBfTmiBAYPPvgggwIi8sVMAVFmG2hQEHdDJAkIJBiQyxHtDyQRERFdGPICgcAZuQmSROPHjx/XQYGMJ7j99tvZfUBEKdmZgp/9wWpYEFHmeHfR6YF3H7S0tJwZPXo05syZozMGMpZA7oUgwcG+fft8g4Jp9R/qRz/7/scl+tErEHBPMyggyl7uoGAdbwJKlDHuiQwuKNC/U3DbbbfpGQkIJEuQ1u8UnDyKXcEpnkXWERERUXYJSIvdfa+DjRs36la83EI5pb6TOKF28yqyjoiIiLJLwB5YKI/PP/88xo4di3nz5jm/V+Crtw+9p9SDKjc9cjCu4OLv4vJ//0SXon8/ZHYYCnK7Y3Mvb1O8b+kt25Ui1KkmO0Motaf7E6lxHbtGHeUsDOS8REREGUBffSBdBX/+859x9OhR/OIXv3AqxpT6enGkB7oId/fBjf86NtaVMOQ/l1yCho5TuqtDSlN//Zj5tWh1bpHsChYSSSVeDoTNcU91FKIjZVSQeKyE+bjzEhERZT7dffDMM8/oivDOO+/UwYBM+40pmLZqvzXI8F8uxV3rDuoiZtUfxKxVUav7QLG7Eg69tAhjZ860FmayA+1oKynEVDMrlXotB04RZZGDaLk9D6WXqXL7Onxslg69nVhz2TVoOZw47bJrMUpX7lQTXut99jknBnbut1fmoWaj9R3viHtt6r3W08k+3niN+n9xfl6nPG/9d5BQkl7LgJzP/2/nTuDZZ59Fb2+vviGSDDKUgCBllkAFC5IB+O/zJurH1x+egv9W8UP9KOt6TSwhj3decxWwfj1QXY0/jltmrRguOl1vZThKQx1mobBb8PJYjma0oa5AbZfY71A2F1Vtdaj0SiO4jm11KyQeq8bj2O7MgZkOxbonSt3niXvuIdd+nQiVWsuleHeVEJFlCir+8gJuxQzUPnYPLjVL0zdUX/oqOHk8itrFs8189rr6xmpEDxwwc5a3X9qAW2+0X9sMFO2v93jPdmLrw2+Z6XPv6tVn0PqhFPP38Lo137RQ1VOUUkDGDthXHNgDDiVQkMsSPZkBhuLZfxxHy75ePa0f1br/eOFTyG8kLrj2Krz33nu4Su68uHu33mZomIpXV5R2v7+qdAvqUBS2Uv+b0aIq6ERlaDoVRpXd/ZDU7yDrO1DRUpBQAcuxW1Bhd1mEgfrQ1IRjNfVzbKGed/tcc4wqtNWt7f+5R9airihs7aNKv10lRHT+HQ7j1WlBVEwy89nsx4Uo2roNb5tZqezf2FqNmbPMrDJ5GvDqq4nZhG3YPr9aVciUbXT3wahRo/RVB0899ZQOCCQ4cF+REKe3Dyf6gJsmj9WlbNJovbhsinpU634xcyKqXr4E760HrrrqKlRXVyNvwwb8+uhjeruz5x5T0KSqcqWzA9GSBiw3lWZ+bVBV0IORj9pWddyOBkTLTWAgx3YHIuXNaGuPj5zTo563/QQlK6GO2iHZgFTPfWohSprL47MKRJQm0/LfuNgjfezqalBlzS7Z9mZsx1sIXauWmZR4XBraJ02e6ONXWzDZaUn3xzzHXetQY84Tl+I+7F6+zpXJsPZbs1JS9It1pe37XOOO4c6iKq519nHiTCrH9cUb8MYuM68r+7m42syKSYuDmPzwWte+dqZkrpm3ntsa+xj2a7azC/IcUr7fya+13+fdn7j93c9NSbXOkfj3YxbngICMI5g7dy4WLVoE+c0CGWgov2b461//2mySoK8X3SoocJe806fQLQMO1bp//p95KK4u1tmB9cW7sXjxYhw7dszaN1vk12JzQwmat9npgqrYAEQp56rJrgcrSvagMiF7QUTpUZX8gblWKnlTNaJ25bVrLULTXjAp5jNYMWs2VrhTzautSj0uDb3VK02eSNLmRXEt6f6p5/g4EJTzvN4IPFwZq/ivXYrJm6znEESLClrc3sKhqZvVuvW6kvZ+rqmOIetacL1JrbduAjYl9blPwYxbZuDQB9by+K4D22zMnO8KHCRTggrMcGVKpBti+0umkleBxSFVRdjZBQmiMNUazeX/frtfazrPO5X490Te80MLXMGW7zqXpL8fszwHBKSyETKwULIG0pUgv3Aolyh6OnHSuRTRLuKNj47jz32znIBAegw2qPLj+fF/xsMivwBFbXVYayrNzlC9R/dBPyIh15UEnQi3tKGkUP2hyrHV0eqHq7WexnPPr21FhwpSojq14DFWIWmaiCyqkrf79mfNVZV+FB/JF7xOi9/c/8AzGVSnW4OSRUiDVHgPLo9rSffPNQZi0j1YMP8tHP5ATR/uUJVnI+abCufShcGEdPwMXH+9q4/c67mmOoasszMjst+CDUnjB8Sl11cAO8L4WLWOP9o/A5N+bFa4XL1YVZ6PW4M7316vKtUlCWM65P3e32GtfymK65fEjvnWDsReh+/77XqtaT5vX3p/VxdI4nvut84t3b+fLBSQlq90H0h3gTzKGAMZeOj7i4Yn+tB9AnFl+vfG4tr/+C9JAUHj344j2vxfzY5DxT2mwB6wV4amcBWay61llSpK9e4+KMPcKvdgQJeyArQ7xy3Qffmt+npCdeyOBqidnHNa+yYeK8WxU0rx3F2/m1BQV4Qgr28kGhrqy75JtfCC6hMnFYtn+lfSyAuA3+vW4AHUqq+31Ky0eVxFjamYlLifrniK8CPPMQdS8ZrJgRjwc7VVm31MMRmSONKFgBa8tSs5A+BwtlmHTftjQYjDXn94J97Yr44xS+bb8bE7qzCg15DG8x5O6fz9ZCn9OwUnTpzQmQH7UW6hLMWTChaq730+rhzanofi9dVJAcHQk8GArjS+KlbFLauaXMtq1Xb2bwTIPrHfCyhrMvt6DjSMHTduvUnjJ65LPFb8vPu88c8had793Muh2jJFKJB1ruXO+Anf4yaeg4j6c+nCN/H0g7H0eJwP2hEtLrRavFJ5qe+1lDwHGE7Bj6apVu2y2CWS0pKOxvXLvxUbqKfPY1qqkwowefdSbDUVzscb6/2zFX7PNdUxZB02pJF6ly4EILRgKXBLuc9VHVNQsaQoxTbWMV5dVo9Der3MR/HG+vbY9um+32k/bx9m/1h3hwpk7MGTqdZ5SPn3k6Wcml+6DuzHVAMN928qc8o//tdNujiqq3VAsK612yyggYqsrYv/vQQiSpMM/jKDBV2VsCcnTZ2HOx4uwgJ9qZr0jZu0tAxym7UctViKO2S7Ze2Y3E/r22+A4dWrVavXPo4qv1Mt6afjWrYzMPmA1eIs1f3Z1hgBeT4rNlVj+wJrv3rVovYdze/7XFMdQ63TYximWueW4jOYUroQihK7KxLJcyiuNu9lMt0NoeoH+xgyf2irK7OS9vud/vP2Zu1/yLwnpXp8gus9913n4vn3kxtk4IAVDXhI99bJMgZBxQNaKNSjl9vr3I9e07xLovwWQQHq2sysHtRoZwWIMhvvkmjbiTW3d2D+Xwb6+whqv8vqMen1N/u/hFHS69e2Y4EZWEiUyqDvkmgez4qMQZBgQAoNlLkMMqmbgIiyh2phDjggGBjd7WCn14mGyZAEBURENNTir4X/3dZq/H6YAw8iBgVEROfNbKz40K/rQH622TXCnt0GdA4MyZgCkThtz7sfvaY5poAoe7nHFBBRZhnMmIIBBwW//e1vzVSyxx9/XD8uWbJEPyZ67DHrp44ZFBDlBvnCeeCBB8wcEWWacxIUbNiwwczFyD0O7KBArkZIJOsZFBDlFvnCIaLMNqxBQU1NDZ544gk8//zzZgnw85//PCkoSFwv91ZobGzU8wwKiHLDQFshRJTZBjzQUC6bO3nipJ4uKyvTRX4aefbNN+tlwmu97EdERESZa8BBQd+pPvSe6MWYMWPw2muv6SK/U/DT4tjPT8n6WbNmYUc4rIu+l4La7+zJTX/87y3QGSrFCPumQJ0hlPIGQURERGkbeFBwsg89vdaPFN34zD/r8q179+OH9V9gTG0UL+zcqdd/a+u38G+lpbr09PTo/YZGCUqi9R6VfQRrYz8LaO5XMJT3AuBdCImIKLcNOCg4qVr8Pcdj9zZ4b32xU4RkDOz13/vL99DT3a2L7DdUioqAlnBC7RzZhuaqKp+7IxIREVF/Bj6m4EQfjtlBwZEjaH4fTpH5H9b/SBdtN/DD236kt5f9hkrh8iCK6taqtrutE6H6KBqWzzXzIqFlr7sTrNsQl4ZCrnXWdjU10vVQo48ZqbG200V3Vcg25Wi2b9tsd1+4jmnvS0RElK0GninoO4nu48esmf/8T3zdC6fI/P+peV8XCQik/L///ZHeXvYbOmWYW9WMbXYt3BlGCypQ7ttVoCr1gjoUha37C2xWWzebNZY2RAs3O/cdcG6BfCqMqmbpqpDbEqtplKChQy3Xt0aWY6qzyrxsGwbq2bdARERZbBBBQR+OHz9uzRw5gqeWbHCKzH/w4YfWehUQvLmuFR999JGel/2GUtnyBkTrQ5BqWG43XBSshW9M0NmBaEkDlps7DeXXBhO6GUpQ4Y4oIjWm9S/ZAR9yTDtzINuWN6Ot/YBZSURElH2coGDkyJFmCvrKAj99OijoxtFjx/CX4Hhd/rp6sn7sebMSH34gQUG3WvZX/P3vf8e77/5dz8t+Qyq/HBWqxR+OhFAfjVX4Z026BMqBsM4UdKChxCz3JLc5NpkCKTqDQERElJ10UBAIBPRvCUiLNy8vT18tcPHFF+sNvHR3d+PQwU5cpPa7KDBCz4d37NDrng8/r+f37NmDyZMnIz8/X8/3qeMPrXzUBotQV14H1cz3zxKI/AIUtdVhrTMUoN4/A3CgHW0lhZgq09It4bqgIY4cUx0lucvAPZbBb5qIiCjz6KDg9OnTeOqpp/Dss8/iySef1IGBVOReent69dUE3//+93HkyNc48vURHUT84x/7U64/deq0Xj+kyparlnwVgv1ed1iGpnAVmsutVH8lKvyvUpBjog4F0iVQ2Y4iJ1Mg4xjcAw3VMTsaoBaYrgZ7ORERUXbSP3MsFZrYtGmT7jq4++67dbr//vvvT/qZ4xnXXCO/U2zm8tR/Mq3+VUf62xtv4N9mzvRd/+orr+il5/1njqWLoKAdQTOwkIgGhz9zTJRbdKbA7hOXbgQZWyBZAulO8PJma6v1+OabaG39G/6m5lUVrwMCYT++/vrrqryGXa+9pte/+847enkmkIGJThcBERERac5AQ8kWSEDgzgr4kYDArdUECrY3TGBgk59CPnbMXMZ4XnQiVGpS/KqUN1ch3JriagUiIqILDvD/Aev07ryVUTmXAAAAAElFTkSuQmCC&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Mount the VMware Tools installation media:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;mkdir /mnt/cd&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;mount /dev/cdrom /mnt/cd&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: inherit;&quot;&gt;Expected warning:&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;mount: block device /dev/sr0 is write-protected, mounting read-only&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Extract the installer:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;cp /mnt/cd/VMwareTools-9.0.10-1481436.tar.gz /tmp/&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;umount /mnt/cd&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;cd /tmp&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;tar xvf VMwareTools-9.0.10-1481436.tar.gz&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;cd vmware-tools-distrib/&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Install tools (accepting all defaults):&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;sudo ./vmware-install.pl -d&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot the VM to verify that the service starts up automatically as expected.&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;shutdown -r now&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/398974078253067653/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2014/04/install-vmware-tools-on-rhel-6-or.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/398974078253067653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/398974078253067653'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2014/04/install-vmware-tools-on-rhel-6-or.html' title='Install VMware Tools on RHEL 6 or CentOS 6'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-8520075734912586461</id><published>2013-09-30T09:57:00.003-05:00</published><updated>2014-05-16T12:39:06.981-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="CentOS"/><category scheme="http://www.blogger.com/atom/ns#" term="ESX"/><category scheme="http://www.blogger.com/atom/ns#" term="ESXi"/><category scheme="http://www.blogger.com/atom/ns#" term="RedHat"/><category scheme="http://www.blogger.com/atom/ns#" term="vCenter"/><category scheme="http://www.blogger.com/atom/ns#" term="VMware"/><title type='text'>Extend a volume in RedHat 6 or CentOS 6</title><content type='html'>To extend a partition on a VM on CentOS 6 or RHEL 6, do the following:&lt;br /&gt;
&lt;br /&gt;
Extend the Partition in vSphere to the size that you need:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5fZ119OzpgmsRxuw3SqNarKJPIhF2zMZZ-APBGF6LFncRcquIl6Cnz7Pv4BLYAKkVGQjYoDN86cDmk1I2hk-pOgR9ePItH7dPX64TmuiNT7A-pZy7N_mD3uVcQsCuQ8C1HZCtyK48esw/s1600/extend.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5fZ119OzpgmsRxuw3SqNarKJPIhF2zMZZ-APBGF6LFncRcquIl6Cnz7Pv4BLYAKkVGQjYoDN86cDmk1I2hk-pOgR9ePItH7dPX64TmuiNT7A-pZy7N_mD3uVcQsCuQ8C1HZCtyK48esw/s1600/extend.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
in the VM, refresh the Partition Tables by the following command:&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;echo 1 &amp;gt; /sys/block/sda/device/rescan&lt;/span&gt;&lt;br /&gt;
Run fdisk to create a new primary partition:&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;fdisk /dev/sda&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Press &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;&lt;b&gt;p&lt;/b&gt;&lt;/span&gt; to print the number of partitions&lt;br /&gt;
Press &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;&lt;b&gt;n&lt;/b&gt;&lt;/span&gt; to create a new primary patition&lt;br /&gt;
Press &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;&lt;b&gt;p&lt;/b&gt;&lt;/span&gt; for primary&lt;br /&gt;
The partition number should automatically be selected, and press enter twice to accept the beginning and ending blocks on the free space.&lt;br /&gt;
Press &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;&lt;b&gt;w&lt;/b&gt;&lt;/span&gt; to write the changes.&lt;br /&gt;
&lt;br /&gt;
Reboot the system: &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;shutdown -r now&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Verify that the new partition exists:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;fdisk -l&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Convert the new partition to a physical volume:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;pvcreate /dev/sda3&lt;/span&gt;&lt;br /&gt;
Extend the Physical Volume (run &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;vgdisplay&lt;/span&gt; to obtain the name of the Volume Group; default is &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;VolGroup00&lt;/span&gt;):&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;vgextend VolGroup00 /dev/sda3&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Extend the Logical Volume (run &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;vgdisplay&lt;/span&gt; to obtain the free space and replace &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;#&lt;/span&gt; below, and &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;lvdisplay&lt;/span&gt; to obtain the name of the Logical Volume; default is &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;/dev/VolGroup00/LogVol00&lt;/span&gt;)&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;lvextend -L+#G /dev/VolGroup00/LogVol00&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Expand the ext3 online using the following command (substituting your proper Volume Group and Logical Volume names):&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;resize2fs&amp;nbsp;/dev/VolGroup00/LogVol00&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Confirm that your new space is available:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;df -h&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: inherit;&quot;&gt;This was written using &lt;a href=&quot;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1006371&quot; target=&quot;_blank&quot;&gt;VMware&#39;s KB article&lt;/a&gt; on the subject as a reference.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/8520075734912586461/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2013/09/extend-volume-in-redhat-6-or-centos-6.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/8520075734912586461'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/8520075734912586461'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2013/09/extend-volume-in-redhat-6-or-centos-6.html' title='Extend a volume in RedHat 6 or CentOS 6'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5fZ119OzpgmsRxuw3SqNarKJPIhF2zMZZ-APBGF6LFncRcquIl6Cnz7Pv4BLYAKkVGQjYoDN86cDmk1I2hk-pOgR9ePItH7dPX64TmuiNT7A-pZy7N_mD3uVcQsCuQ8C1HZCtyK48esw/s72-c/extend.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-6159294334006397147</id><published>2012-07-19T08:27:00.002-05:00</published><updated>2012-07-19T08:27:49.757-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Backup"/><category scheme="http://www.blogger.com/atom/ns#" term="Best Practice"/><category scheme="http://www.blogger.com/atom/ns#" term="ESX"/><category scheme="http://www.blogger.com/atom/ns#" term="ESXi"/><category scheme="http://www.blogger.com/atom/ns#" term="Quest"/><category scheme="http://www.blogger.com/atom/ns#" term="vCenter"/><category scheme="http://www.blogger.com/atom/ns#" term="vRanger"/><title type='text'>vRanger 5 and ESXi Performance Settings</title><content type='html'>Everyone should know that the previous recommendations from Quest were to increase the CPU Reservations to 1500 on ESX servers for the best performance from vRanger.&lt;br /&gt;
&lt;br /&gt;
I just recently ran across an article &lt;a href=&quot;http://communities.quest.com/thread/11804&quot; target=&quot;_blank&quot;&gt;(here)&lt;/a&gt; from Sept 2011 detailing that this is NOT the case for ESXi. There is no performance gain on ESXi by increasing the CPU reservations from the default 293.&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/6159294334006397147/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2012/07/vranger-5-and-esxi-performance-settings.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/6159294334006397147'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/6159294334006397147'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2012/07/vranger-5-and-esxi-performance-settings.html' title='vRanger 5 and ESXi Performance Settings'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-4613190232170818709</id><published>2012-07-19T08:10:00.000-05:00</published><updated>2012-07-19T08:10:06.158-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Backup"/><category scheme="http://www.blogger.com/atom/ns#" term="Error"/><category scheme="http://www.blogger.com/atom/ns#" term="ESX"/><category scheme="http://www.blogger.com/atom/ns#" term="Quest"/><category scheme="http://www.blogger.com/atom/ns#" term="vCenter"/><category scheme="http://www.blogger.com/atom/ns#" term="VMware"/><category scheme="http://www.blogger.com/atom/ns#" term="vRanger"/><title type='text'>vRanger error &quot;There is an error in XML document&quot;</title><content type='html'>I ran into an issue with one of our repositories - every job in the particular repository was failing with the error:&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;An internal error occurred during execution, please contact Quest support if the error persists. Error Message: There is an error in XML document (823, 223).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This error is commonly caused by a corruption or issue with the manifest file as detailed here.&lt;br /&gt;&lt;br /&gt;To fix it, go into the manifest file for the repository &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;(GlobalManifest.metadata)&lt;/span&gt;, make sure that all trailing brackets are closed, and add &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;&amp;lt;/vRangerGlobalManifestFile&amp;gt;&lt;/span&gt; at the end of the document. &lt;br /&gt;&lt;br /&gt;Save and test.&lt;br /&gt;&lt;br /&gt;------&lt;br /&gt;&lt;br /&gt;Dustin Shaw&lt;br /&gt;VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/4613190232170818709/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2012/07/vranger-error-there-is-error-in-xml.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/4613190232170818709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/4613190232170818709'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2012/07/vranger-error-there-is-error-in-xml.html' title='vRanger error &quot;There is an error in XML document&quot;'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-2212016528160409522</id><published>2012-05-24T07:02:00.000-05:00</published><updated>2012-05-24T07:02:45.984-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Disaster Recovery"/><category scheme="http://www.blogger.com/atom/ns#" term="ESX"/><category scheme="http://www.blogger.com/atom/ns#" term="ESXi"/><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft"/><category scheme="http://www.blogger.com/atom/ns#" term="SQL"/><category scheme="http://www.blogger.com/atom/ns#" term="vCenter"/><category scheme="http://www.blogger.com/atom/ns#" term="VMware"/><title type='text'>vCenter Server 5 Service Fails</title><content type='html'>We had an issue with the vCenter Server 5 Service failing recently. Basically what happened was the VMware VirtualCenter Server service failed (out of the blue) with the following Informational Event ID 1000 logged in the Application log:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;The description for Event ID 1000 from source VMware VirtualCenter Server cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.&lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;If the event originated on another computer, the display information had to be saved with the event.&lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;The following information was included with the event: &lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;Starting VMware VirtualCenter 5.0.0 build-623373&lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;the message resource is present but the message is not found in the string/message table&lt;/span&gt;&lt;/blockquote&gt;
&lt;br /&gt;
Followed by another Info Event 1000:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;The description for Event ID 1000 from source VMware VirtualCenter Server cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.&lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;If the event originated on another computer, the display information had to be saved with the event.&lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;The following information was included with the event: &lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;Log directory: C:\ProgramData\VMware\VMware VirtualCenter\Logs.&lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;the message resource is present but the message is not found in the string/message table&lt;/span&gt;&lt;/blockquote&gt;
And followed by an Error Event 1000 (upon it attempting to auto-restart the service):&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;The description for Event ID 1000 from source VMware VirtualCenter Server cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.&lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;If the event originated on another computer, the display information had to be saved with the event.&lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;The following information was included with the event: &lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;Failed to intialize VMware VirtualCenter. Shutting down...&lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;the message resource is present but the message is not found in the string/message table&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;
First try was to restart all the vCenter services - only the VMware VirtualCenter Server service was offline; all other services (like VMware VirtualCenter Management Webservices) were still online. This obviously failed with the same error as before.&lt;br /&gt;
&lt;br /&gt;
All of the SQL services were verified online (these are kept on a separate server due to the size), and accessible. I ran across a &lt;a href=&quot;http://communities.vmware.com/thread/224942&quot; target=&quot;_blank&quot;&gt;similar Discussion thread in VMware Communities&lt;/a&gt;, which pointed to issues inside of the SQL Database. Based off of this, I decided the first order was to look at my SQL server to see what was going on there. I was able to log in, and verified that everything was up. Then I looked at my logs, and saw Event ID 17053:&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;C:\VCDB.ldf: Operating system error 112(There is not enough space on the disk.) encountered.&lt;/span&gt;&lt;/blockquote&gt;
&amp;nbsp;And instantly I knew my problem. Some yahoo (namely the yahoo writing this article) must not&#39;ve been paying attention when installing the VCDB database, and stuck it in the root of the C drive. Naturally, that yahoo had to fix his own problem...&lt;br /&gt;
&lt;br /&gt;
So I went into Microsoft SQL Server Management Studio, and ran the following command:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;alter database VCDB modify file ( name = vcdb , filename = &#39;E:\SQL\MDF\VCDB.mdf&#39; )&lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;alter database VCDB modify file ( name = vcdb_log , filename = &#39;E:\SQL\LDF\VCDB.ldf&#39;)&lt;/span&gt;&lt;br style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot; /&gt;&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;&quot;&gt;go&lt;/span&gt;&lt;/blockquote&gt;
Then I Offlined the database (Right click, Tasks, Take Offline), and moved the files to their new homes. Then I Onlined the database, and verified that the path was correct for it. You can see the full process of how to &lt;a href=&quot;http://msdn.microsoft.com/en-us/library/ms345408.aspx&quot; target=&quot;_blank&quot;&gt;move a SQL database here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Once this was done, I went back to my vCenter Server, and was able to bring all my services online without incident, and was able to again go in and manage my vCenter 5 Server via vSphere Client.&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/2212016528160409522/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2012/05/vcenter-server-5-service-fails.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/2212016528160409522'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/2212016528160409522'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2012/05/vcenter-server-5-service-fails.html' title='vCenter Server 5 Service Fails'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-3230495134386593654</id><published>2012-03-13T06:22:00.000-05:00</published><updated>2012-03-13T06:22:22.088-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="2003"/><category scheme="http://www.blogger.com/atom/ns#" term="ESX"/><category scheme="http://www.blogger.com/atom/ns#" term="ESXi"/><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft"/><category scheme="http://www.blogger.com/atom/ns#" term="VMware"/><category scheme="http://www.blogger.com/atom/ns#" term="Windows Server"/><title type='text'>WNLB and VMware</title><content type='html'>So I believe I&#39;ve found an (known) issue with 2003 Windows Network Load Balancing and VMware.&lt;br /&gt;
VMware reports that WNLB on Windows 2003 Servers does not behave as expected &lt;a href=&quot;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1556&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt;. Basically the article says the the NLB will point to one of the servers, not all of them, when running in unicast. They give you two fixes: use multicast;&amp;nbsp;or reconfigure your Port Groups (or vSwitches) to prevent RARP Packet Transmissions. Interesting thing, with the current environment these servers are hosted in, I am unable to either run multicast or disable Switch Notify. I&#39;ll have to take that up with the Network Team, or perhaps investigate some NLB hardware.&lt;br /&gt;
&lt;br /&gt;
So here&#39;s where I&#39;m left with - these servers are not supposed to go down (hence the NLB), but they are everyday at 4AM (fun call). This is when backups are running, so I&#39;m adjusting the time to see if the issue follows.&lt;br /&gt;
&lt;br /&gt;
What appears to be happening is that when snapshots are taken for backups, the NLB seems to freak out at the one dropped ping. Currently the backups all run at once, which makes them all hiccup at the same time, killing the NLB for a good reported 45 minutes (no idea why so long). If the issue follows the backups, perhaps staggering the backups might solve the problem (let the NLB roll from one server to another).&lt;br /&gt;
&lt;br /&gt;
I&#39;ll keep you posted on what I find.&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/3230495134386593654/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2012/03/wnlb-and-vmware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/3230495134386593654'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/3230495134386593654'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2012/03/wnlb-and-vmware.html' title='WNLB and VMware'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-8035014945076026360</id><published>2012-02-23T08:39:00.000-06:00</published><updated>2012-02-23T08:40:15.844-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Error"/><category scheme="http://www.blogger.com/atom/ns#" term="ESX"/><category scheme="http://www.blogger.com/atom/ns#" term="ESXi"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><category scheme="http://www.blogger.com/atom/ns#" term="vCenter"/><category scheme="http://www.blogger.com/atom/ns#" term="VMware"/><title type='text'>Host update fails after updating to 4.1u2</title><content type='html'>After updating vCenter Update Manager (right after updating my vCenter Server) from 4.1u1 to 4.1u2, I received the following error when trying to update on of my hosts:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3zvV5gskUjzkNdoRl2CWmZd-nPJZqbeO_q7XJleiVfqpYGDbult5v4mU8oL6no-GQrd0KtgRNHmmYxJavGEA1ek_qq0TEg1BYo2IaueSUlkpk4NOKYhuYHnohuq2c-3Xn7F_3wp-aKUg/s1600/RemediateNotFound.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;26&quot; lda=&quot;true&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3zvV5gskUjzkNdoRl2CWmZd-nPJZqbeO_q7XJleiVfqpYGDbult5v4mU8oL6no-GQrd0KtgRNHmmYxJavGEA1ek_qq0TEg1BYo2IaueSUlkpk4NOKYhuYHnohuq2c-3Xn7F_3wp-aKUg/s400/RemediateNotFound.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;Remediation did not succeed for esxihost: SingleHostRemediate: esxupdate error, version: 1.30, operation: 7: (&#39;http://esxihost:9084/vci/hostupdates/hostupdate/vmw/vibs/cross_oem-vmware-esx-drivers-net-vxge_400.2.0.28.21239-1OEM.vib&#39;,&#39;/var/tmp/cache/-1699692350&#39;,&#39;[Errno 14] HTTP Error 404: Not Found&#39;)&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
After doing some research, I discovered what happened is that Update Manager 4.1u2 is case sensitive, whereas 4.1u1 was not. Any patches that were downloaded previous to the 4.1u2 update that contain upper case letters will fail with this error. VMware has a &lt;a href=&quot;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=2011656&quot; target=&quot;_blank&quot;&gt;KB article about it here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
The patches affected are the ones below. I&#39;ve put the correct capitalization on them for you. If you go to your patch repository, you can rename the files that you have to the below, and you should then be able to update your hosts. The repositories are located here:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Windows2008: &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;C:\ProgramData\VMware\VMware Update Manager\Data\Hostupdate\vmw\vib\ &lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Windows2003: &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;C:\Documents and Settings\All Users\Application Data\VMware\VMware Update Manager\Data\Hostupdate\vmw\vib&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;bind-libs-9.3.6-4.P1.el5_5.3.i386.vib &lt;br /&gt;bind-libs-9.3.6-4.P1.el5_5.3.x86_64.vib &lt;br /&gt;bind-utils-9.3.6-4.P1.el5_5.3.x86_64.vib &lt;br /&gt;bind-libs-9.3.6-4.P1.el5_5.3.i386.vib &lt;br /&gt;cross_oem-vmware-esx-drivers-net-vxge_400.2.0.28.21239-1OEM.vib &lt;br /&gt;cross_oem-vmware-esx-drivers-scsi-3w-9xxx_400.2.26.08.036vm40-1OEM.vib &lt;br /&gt;vmware-esx_swMgmt_provider-4x.1.0.1-1.4.348481.vib &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/8035014945076026360/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2012/02/host-update-fails-after-updating-to.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/8035014945076026360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/8035014945076026360'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2012/02/host-update-fails-after-updating-to.html' title='Host update fails after updating to 4.1u2'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3zvV5gskUjzkNdoRl2CWmZd-nPJZqbeO_q7XJleiVfqpYGDbult5v4mU8oL6no-GQrd0KtgRNHmmYxJavGEA1ek_qq0TEg1BYo2IaueSUlkpk4NOKYhuYHnohuq2c-3Xn7F_3wp-aKUg/s72-c/RemediateNotFound.PNG" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7636955539235835573.post-7635494342114863298</id><published>2012-02-22T11:27:00.000-06:00</published><updated>2012-02-22T11:27:05.822-06:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Error"/><category scheme="http://www.blogger.com/atom/ns#" term="ESXi"/><category scheme="http://www.blogger.com/atom/ns#" term="Updates"/><category scheme="http://www.blogger.com/atom/ns#" term="VMware"/><title type='text'>Syslog not configured on ESXi 4.1u2</title><content type='html'>When I updated my ESXi host from 4.1u1 to 4.1u2, I got the following error message:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj86mbzL2xm4RgjEcv12AXwXHXQgEG1zt2pc8riDU67F30YQYZgK1hGLSjM2MDsTB5-2JD97l-AVwC_nD-8DQrFqQcmVcnDzoJ6YY6E0rW_QkcVP6bGhVZo3o9gttGcKz5NFaYBKSXdPMQ/s1600/esxisyslog.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;28&quot; lda=&quot;true&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj86mbzL2xm4RgjEcv12AXwXHXQgEG1zt2pc8riDU67F30YQYZgK1hGLSjM2MDsTB5-2JD97l-AVwC_nD-8DQrFqQcmVcnDzoJ6YY6E0rW_QkcVP6bGhVZo3o9gttGcKz5NFaYBKSXdPMQ/s320/esxisyslog.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;Configuration Issues&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;Issue detected on esxihost in datacenter: Warning: Syslog not configured. Please check Syslog options under Configuration.Software.Advanced Settings in vSphere client.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;I thought it was odd since the host previously never complained about the Syslog before. I compared the settings between it and the other 4.1u2 hosts that I had, and indeed, it was missing the &lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;Syslog.Local.DatastorePath&lt;/span&gt; setting.&lt;br /&gt;
&lt;br /&gt;
The setting on my hosts was:&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Courier New&amp;quot;, Courier, monospace;&quot;&gt;[] /scratch/log/messages&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Once I copied this into my Syslog.Local.DatastorePath setting on the server, it was happy. I went ahead and copied the setting to my remaining 4.1u1 servers so that they will be happy when updated as well.&lt;br /&gt;
&lt;br /&gt;
So apparently ESXi 4.1u2 has issues with the Syslog running on ramdisk, but ESXi 4.1u1 doesn&#39;t.&lt;br /&gt;
&lt;br /&gt;
I found the following VMware KB Article that explains why it complains about it:&lt;br /&gt;
&lt;a href=&quot;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1032460&quot; target=&quot;_blank&quot;&gt;Syslog not configured messages on ESXi host console or in logs&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
------&lt;br /&gt;
Dustin Shaw&lt;br /&gt;
VCP</content><link rel='replies' type='application/atom+xml' href='http://www.virtualizetheworld.com/feeds/7635494342114863298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.virtualizetheworld.com/2012/02/syslog-not-configured-on-esxi-41u2.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/7635494342114863298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7636955539235835573/posts/default/7635494342114863298'/><link rel='alternate' type='text/html' href='http://www.virtualizetheworld.com/2012/02/syslog-not-configured-on-esxi-41u2.html' title='Syslog not configured on ESXi 4.1u2'/><author><name>Shaw</name><uri>http://www.blogger.com/profile/00292984112665431323</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj86mbzL2xm4RgjEcv12AXwXHXQgEG1zt2pc8riDU67F30YQYZgK1hGLSjM2MDsTB5-2JD97l-AVwC_nD-8DQrFqQcmVcnDzoJ6YY6E0rW_QkcVP6bGhVZo3o9gttGcKz5NFaYBKSXdPMQ/s72-c/esxisyslog.PNG" height="72" width="72"/><thr:total>0</thr:total></entry></feed>