Avatar

Nathan Beltran

  • Total activity 56
  • Last activity
  • Member since
  • Following 0 users
  • Followed by 0 users
  • Votes 2
  • Subscriptions 35

Activity overview

Latest activity by Nathan Beltran
  • Avatar

    Nathan Beltran created an article,

    Display Message Preferences not being saved

    Problem: When trying to save my display preferences, for example, changing the sort order from Recent messages first to Oldest message first after saving this setting it does display the oldest log...

  • Avatar

    Nathan Beltran created an article,

    Error in my query while looking up from Threat Intel

    Question: Why am I receiving the error  "Lookup: file=/{ORGID}/sumo:/threat/cs doesn't exist."  when using the Sumo Logic Threat lookup database.   Answer: The Sumo Logic Threat Intel loo...

  • Avatar

    Nathan Beltran created an article,

    Log showing empty Message field

    Problem:  We are seeing empty fields in our logs but it is showing that the logs do have a file size using "| _size as size".   Cause: The empty fields aren't actually blank but are NULL...

  • Avatar

    Nathan Beltran created an article,

    Windows 2003 Event logs ingestion

    Question: Can I collect event logs on Windows 2003?  Answer: Due to system library limitations, Sumo Logic, unfortunately, cannot collect Windows Events from Windows 2003 servers and therefore does...

  • Avatar

    Nathan Beltran commented,

    It should be possible. Can you please provide a log sample and tell us which fields you need to parse?

  • Avatar

    Nathan Beltran commented,

    I would recommend checking the version of curl. Here is a KB that you can refer to.   https://support.sumologic.com/hc/en-us/articles/360006640534-SSL-error-when-running-a-curl-request-to-the-API  ...

  • Avatar

    Nathan Beltran commented,

    Santosh, You have a couple of options you can use. The first option would be using a "where" statement. With the where statement you also have the "not" option to return results...

  • Avatar

    Nathan Beltran commented,

    Alex, Here is a better alternative. Using parse with the multi option. | json field=_raw "waf.riskTuples" as t| json field=_raw "waf.riskScores" as r| parse regex field= t "...

  • Avatar

    Nathan Beltran commented,

    Alex, Here is one way to do it without using parse multi. The only gotcha is that you will have to create a parse statement for each set of arrays. For example, the parse statement below will parse...

  • Avatar

    Nathan Beltran created an article,

    Returning a value of "0" using the count operator

    Question: How do I return a value of "0" when running a query using the count operator where the query returns no values or results?  Answer: You can use a combination of the fillmissing ...