in her last lesson, we were building up to Rogic's. In order to capture those custom properties, we had to take a short break. However, let's continue where we left off.
I just mentioned you can actually modify it,
So you can come here
right? And then that expand this again so I could see more. There we go.
And there we go. Never gonna do Let's say source port right here. So I'm gonna call it P f sense
and I'm gonna show you how capture works room now.
So you have one friend. ISS is here and the other one here, right? And that's why I was talking about that We can actually modify. So if you come here
actually added a wrong, then we'll apologize.
And this can actually gonna do
this is well right. You can see
marking this one. However, if we change to capture group to capture 22 you see it now captured the source. I s or support. I apologize. And if you go to three, it captures the destination port so you can see that you can actually use the same Roger can just change a little valley at the end as well, and it's a good option a swell to do this. So
in this case, for example, I can copy it. Is it too? Because it's gonna be a sore sport, right? For PF sends
it's safe and then you can literally come again.
It's gonna be like a fast value at the tragic
destination poured. And then here come 23 test. It's working, and you're gonna make sure
on the tom it's highlighted. And this is itself highlighting. I don't have any search functions, as you can see, And then it's safe. And now you can see that you're getting 1234 different values, right? The other thing, we gotta search it. Search for the action itself, in this case, the action being blocked. Right?
So let's go back to the D. S. N.
Apologies a customer even extract
I'm gonna do PF sense action, right? In this case, we can type the whole thing even though we're not gonna use the holding because technically, we have to get up to here and the last thing's curator process the battery in my opinion so I can come up to here, for example,
and stop this and see how much it attacks. And that's pretty good. Let's remove two more.
So around here and elite, I like to leave the coma in their ***, A lasting to the tack
it doesn't keep searching for more information. You have found the coma. That's it. It's not gonna be like a W. Plus, this is all that's a lot of characters. No,
stop in a coma if there's a space. Even better in many, many software do have spaces when they're sending sister locks, and I will use this space itself to determine where a variable lens. So now we have it here, right?
You're gonna add that capture group right here.
You actually wrote that by accident?
You're a period for some reason.
block right. Test it, Detective. I know it's on the top, always attracted,
and it's safe. And now you should see the action source poured Destination port sort sport source. I pian destination. I pee into default domain and this basically it to wrap up for how to create custom properties. Now, obviously, if you go back to return to event, lose right
when you come here, you can now see,
See, it still says this, but if you come to at it, search right.
And the second front to load
it's taking a little bit longer than a second. There we go. And we're gonna do
It's just keeping us is five minutes. Right? And now here, we're gonna search for a p of sense,
And all of these variables we're gonna add in here.
Okay, So I'm gonna grab all of them
and put him in there and then all of them
and moved him up. Up, up, up, up, up, up, up, up.
Right. Except one thing I do want to have in the top is e start time,
And that's its search.
And you can see I will perform the surge. And here we go. And here's itself how you can see the
curator data formatted to RPF sends so you can see the answers in actions block from this source. I p to this destination. I pee. Sorry. Destination port. Ah, source Port start sleepy. Now, if you don't like the order, you can always come back and its search
right. And here you can. Don't say OK, I want to see the source. I pee first.
So our sleepy following a dissonant bite. A sore sport? Let's see,
followed by the destination eyepiece alibi, the destination port and the harder I want youto action beginning or the end whistle I want It's the first thing I want to see. So let's go with port
and then search again.
Here you go, Right. Sore sleepy source. Forward Destination I p Destination poured and named Locke sorts, et cetera. You can see you can play around. Once you do that, you can save the criteria. You can say this is P F Sense.
All right, you can, including a quick search chair with everyone, in case somebody else wants to use that really time because you want to see the real time you can set. Ask your default search. That way, whenever you come into lock searching, you see the PF sense log. Okay. Now one of the pros and cons. That's obviously that this is very specific for this,
if you have other locks, sources And obviously you won't see the data or the eyepiece will not match. And therefore, that's the option of the universal, the Ascender you can create
Farmer. This is the wrap up for today and carry on.
What did we learn today? We created custom properties for new Luxor. Speed of sense. Inside Curator.
It took a little bit of building using Rand Texas.
And if you're not familiar with them, I highly recommend the Reddick scores on some Red X tutorials.
In order to build these custom, Red X is in your own environment.
In our next lesson, we're actually gonna go over and used a custom to you send for P f Sense. You will notice that this integration it's more complete and better overall for even correlation
Hope to see soon. Have a great day.