<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Nifi - Extract value from XML content and add it as attribute in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Extract-value-from-XML-content-and-add-it-as-attribute/m-p/307070#M223065</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using NIFI&amp;nbsp;&lt;SPAN&gt;EvaluateXPath module.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I am trying to extract the value from the first Channel parameter (&lt;STRONG&gt;Microsoft-Windows-Sysmon/Operational&lt;/STRONG&gt;) and add it as an attribute - The channel1 attribute is empty when setting the value to&amp;nbsp; "/Event/System/Channel"&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to understand what should be the Value in the Channel1 property&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;XML&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"&amp;gt;
   &amp;lt;System&amp;gt;
      &amp;lt;Provider Name="Microsoft-Windows-Sysmon"
                Guid="{5770385f-c22a-43e0-bf4c-06f5698ffbd9}"/&amp;gt;
      &amp;lt;EventID&amp;gt;10&amp;lt;/EventID&amp;gt;
      &amp;lt;Version&amp;gt;3&amp;lt;/Version&amp;gt;
      &amp;lt;Level&amp;gt;4&amp;lt;/Level&amp;gt;
      &amp;lt;Task&amp;gt;10&amp;lt;/Task&amp;gt;
      &amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;
      &amp;lt;Keywords&amp;gt;0x8000000000000000&amp;lt;/Keywords&amp;gt;
      &amp;lt;TimeCreated SystemTime="2020-12-03T14:23:35.660463800Z"/&amp;gt;
      &amp;lt;EventRecordID&amp;gt;94211&amp;lt;/EventRecordID&amp;gt;
      &amp;lt;Correlation/&amp;gt;
      &amp;lt;Execution ProcessID="10052" ThreadID="9516"/&amp;gt;
      &amp;lt;Channel&amp;gt;Microsoft-Windows-Sysmon/Operational&amp;lt;/Channel&amp;gt;
      &amp;lt;Computer&amp;gt;workstation.test.com&amp;lt;/Computer&amp;gt;
      &amp;lt;Security UserID="S-1-5-18"/&amp;gt;
   &amp;lt;/System&amp;gt;
   &amp;lt;EventData&amp;gt;
      &amp;lt;Data Name="RuleName"/&amp;gt;
      &amp;lt;Data Name="UtcTime"&amp;gt;2020-12-03 14:23:35.659&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="SourceProcessGUID"&amp;gt;{921b204f-2632-5fc2-0000-0010a0d20100}&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="SourceProcessId"&amp;gt;3428&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="SourceThreadId"&amp;gt;4072&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="SourceImage"&amp;gt;C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MsMpEng.exe&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="TargetProcessGUID"&amp;gt;{921b204f-2636-5fc2-0000-001085f80200}&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="TargetProcessId"&amp;gt;4212&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="TargetImage"&amp;gt;C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\NisSrv.exe&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="GrantedAccess"&amp;gt;0x1400&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="CallTrace"&amp;gt;C:\Windows\SYSTEM32\ntdll.dll+9c584|C:\Windows\System32\KERNELBASE.dll+2730e|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+1c606f|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+103572|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+1093e6|C:\Windows\System32\ucrtbase.dll+20e72|C:\Windows\System32\KERNEL32.DLL+17bd4|C:\Windows\SYSTEM32\ntdll.dll+6ced1&amp;lt;/Data&amp;gt;
   &amp;lt;/EventData&amp;gt;
   &amp;lt;RenderingInfo Culture="en-US"&amp;gt;
      &amp;lt;Message&amp;gt;Process accessed:
RuleName: 
UtcTime: 2020-12-03 14:23:35.659
SourceProcessGUID: {921b204f-2632-5fc2-0000-0010a0d20100}
SourceProcessId: 3428
SourceThreadId: 4072
SourceImage: C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MsMpEng.exe
TargetProcessGUID: {921b204f-2636-5fc2-0000-001085f80200}
TargetProcessId: 4212
TargetImage: C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\NisSrv.exe
GrantedAccess: 0x1400
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9c584|C:\Windows\System32\KERNELBASE.dll+2730e|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+1c606f|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+103572|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+1093e6|C:\Windows\System32\ucrtbase.dll+20e72|C:\Windows\System32\KERNEL32.DLL+17bd4|C:\Windows\SYSTEM32\ntdll.dll+6ced1&amp;lt;/Message&amp;gt;
      &amp;lt;Level&amp;gt;Information&amp;lt;/Level&amp;gt;
      &amp;lt;Task&amp;gt;Process accessed (rule: ProcessAccess)&amp;lt;/Task&amp;gt;
      &amp;lt;Opcode&amp;gt;Info&amp;lt;/Opcode&amp;gt;
      &amp;lt;Channel/&amp;gt;
      &amp;lt;Provider/&amp;gt;
      &amp;lt;Keywords/&amp;gt;
   &amp;lt;/RenderingInfo&amp;gt;
&amp;lt;/Event&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="configuration.JPG" style="width: 762px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/29719i4E8554B3D0C14FB5/image-size/large?v=v2&amp;amp;px=999" role="button" title="configuration.JPG" alt="configuration.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Empty Attribute&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="output.JPG" style="width: 283px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/29720i49737C0E818ED4CE/image-size/large?v=v2&amp;amp;px=999" role="button" title="output.JPG" alt="output.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Dec 2020 06:36:08 GMT</pubDate>
    <dc:creator>dzbeda</dc:creator>
    <dc:date>2020-12-07T06:36:08Z</dc:date>
    <item>
      <title>Nifi - Extract value from XML content and add it as attribute</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Extract-value-from-XML-content-and-add-it-as-attribute/m-p/307070#M223065</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using NIFI&amp;nbsp;&lt;SPAN&gt;EvaluateXPath module.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I am trying to extract the value from the first Channel parameter (&lt;STRONG&gt;Microsoft-Windows-Sysmon/Operational&lt;/STRONG&gt;) and add it as an attribute - The channel1 attribute is empty when setting the value to&amp;nbsp; "/Event/System/Channel"&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to understand what should be the Value in the Channel1 property&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;XML&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;
&amp;lt;Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"&amp;gt;
   &amp;lt;System&amp;gt;
      &amp;lt;Provider Name="Microsoft-Windows-Sysmon"
                Guid="{5770385f-c22a-43e0-bf4c-06f5698ffbd9}"/&amp;gt;
      &amp;lt;EventID&amp;gt;10&amp;lt;/EventID&amp;gt;
      &amp;lt;Version&amp;gt;3&amp;lt;/Version&amp;gt;
      &amp;lt;Level&amp;gt;4&amp;lt;/Level&amp;gt;
      &amp;lt;Task&amp;gt;10&amp;lt;/Task&amp;gt;
      &amp;lt;Opcode&amp;gt;0&amp;lt;/Opcode&amp;gt;
      &amp;lt;Keywords&amp;gt;0x8000000000000000&amp;lt;/Keywords&amp;gt;
      &amp;lt;TimeCreated SystemTime="2020-12-03T14:23:35.660463800Z"/&amp;gt;
      &amp;lt;EventRecordID&amp;gt;94211&amp;lt;/EventRecordID&amp;gt;
      &amp;lt;Correlation/&amp;gt;
      &amp;lt;Execution ProcessID="10052" ThreadID="9516"/&amp;gt;
      &amp;lt;Channel&amp;gt;Microsoft-Windows-Sysmon/Operational&amp;lt;/Channel&amp;gt;
      &amp;lt;Computer&amp;gt;workstation.test.com&amp;lt;/Computer&amp;gt;
      &amp;lt;Security UserID="S-1-5-18"/&amp;gt;
   &amp;lt;/System&amp;gt;
   &amp;lt;EventData&amp;gt;
      &amp;lt;Data Name="RuleName"/&amp;gt;
      &amp;lt;Data Name="UtcTime"&amp;gt;2020-12-03 14:23:35.659&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="SourceProcessGUID"&amp;gt;{921b204f-2632-5fc2-0000-0010a0d20100}&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="SourceProcessId"&amp;gt;3428&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="SourceThreadId"&amp;gt;4072&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="SourceImage"&amp;gt;C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MsMpEng.exe&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="TargetProcessGUID"&amp;gt;{921b204f-2636-5fc2-0000-001085f80200}&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="TargetProcessId"&amp;gt;4212&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="TargetImage"&amp;gt;C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\NisSrv.exe&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="GrantedAccess"&amp;gt;0x1400&amp;lt;/Data&amp;gt;
      &amp;lt;Data Name="CallTrace"&amp;gt;C:\Windows\SYSTEM32\ntdll.dll+9c584|C:\Windows\System32\KERNELBASE.dll+2730e|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+1c606f|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+103572|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+1093e6|C:\Windows\System32\ucrtbase.dll+20e72|C:\Windows\System32\KERNEL32.DLL+17bd4|C:\Windows\SYSTEM32\ntdll.dll+6ced1&amp;lt;/Data&amp;gt;
   &amp;lt;/EventData&amp;gt;
   &amp;lt;RenderingInfo Culture="en-US"&amp;gt;
      &amp;lt;Message&amp;gt;Process accessed:
RuleName: 
UtcTime: 2020-12-03 14:23:35.659
SourceProcessGUID: {921b204f-2632-5fc2-0000-0010a0d20100}
SourceProcessId: 3428
SourceThreadId: 4072
SourceImage: C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MsMpEng.exe
TargetProcessGUID: {921b204f-2636-5fc2-0000-001085f80200}
TargetProcessId: 4212
TargetImage: C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\NisSrv.exe
GrantedAccess: 0x1400
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9c584|C:\Windows\System32\KERNELBASE.dll+2730e|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+1c606f|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+103572|C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\mpsvc.dll+1093e6|C:\Windows\System32\ucrtbase.dll+20e72|C:\Windows\System32\KERNEL32.DLL+17bd4|C:\Windows\SYSTEM32\ntdll.dll+6ced1&amp;lt;/Message&amp;gt;
      &amp;lt;Level&amp;gt;Information&amp;lt;/Level&amp;gt;
      &amp;lt;Task&amp;gt;Process accessed (rule: ProcessAccess)&amp;lt;/Task&amp;gt;
      &amp;lt;Opcode&amp;gt;Info&amp;lt;/Opcode&amp;gt;
      &amp;lt;Channel/&amp;gt;
      &amp;lt;Provider/&amp;gt;
      &amp;lt;Keywords/&amp;gt;
   &amp;lt;/RenderingInfo&amp;gt;
&amp;lt;/Event&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="configuration.JPG" style="width: 762px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/29719i4E8554B3D0C14FB5/image-size/large?v=v2&amp;amp;px=999" role="button" title="configuration.JPG" alt="configuration.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Empty Attribute&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="output.JPG" style="width: 283px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/29720i49737C0E818ED4CE/image-size/large?v=v2&amp;amp;px=999" role="button" title="output.JPG" alt="output.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 06:36:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Extract-value-from-XML-content-and-add-it-as-attribute/m-p/307070#M223065</guid>
      <dc:creator>dzbeda</dc:creator>
      <dc:date>2020-12-07T06:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi - Extract value from XML content and add it as attribute</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Nifi-Extract-value-from-XML-content-and-add-it-as-attribute/m-p/307072#M223066</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/74983"&gt;@dzbeda&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Try it with:&amp;nbsp;&lt;BR /&gt;/*:Event/*:System/*:Channel&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-12-07_HCC_EvaluateXPath.png" style="width: 412px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/29721i97A82A0E5A8FC4F0/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-12-07_HCC_EvaluateXPath.png" alt="2020-12-07_HCC_EvaluateXPath.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 06:50:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Nifi-Extract-value-from-XML-content-and-add-it-as-attribute/m-p/307072#M223066</guid>
      <dc:creator>justenji</dc:creator>
      <dc:date>2020-12-07T06:50:54Z</dc:date>
    </item>
  </channel>
</rss>

