I don't necessary have a problem, as I have a solution. It is just that there may be a better solution.
GOAL: Part one: Parse data from a file using the "\" as a delimiter and extracting only the last delimiter. Part two: Parse same file and extract everything but the last delimited item.
Background: I was given 600+ registry keys that needed to be queried. I was given a file with the concatenated keys and values. IE...HKLM\Software\Microsoft\Driver Signing\Policy. I need the value "Policy" separated from the rest of the key.
Sample data:
HKLM\System\CurrentControlSet\Control\Lsa\LimitBlankPasswordUse
Password Policy security settings are not registry keys.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\DontDisplayLastUserName
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCAD
[snip]......
My Solution:
Part one of the problem was a snap to solve, I ran the following command and got all the values.
awk --field-separator='\' '{ print $NF }' regkeydump
OUTPUT:
LimitBlankPasswordUse
DontDisplayLastUserName
DisableCAD
[snip]......
Perfect, works like a charm. Part two is where problems begin. No matter what I try, I cannot get this command to recognize the "\"
awk 'BEGIN {FS=ORS="\"} {for (i=1;i<NF;i++) print $i}'
So as a work around I replaced the "\" with ":" in my data file
cat regkeydump | tr '\' ':' > regkeydumpprep
Then ran the awk command
awk 'BEGIN {FS=ORS=":"} {for (i=1;i<NF;i++) print $i}' regkeydumpprep |sed 's/$/\n/' > regkeysonly
OUTPUT:
HKLM:System:CurrentControlSet:Control:Lsa:HKLM:Software:Microsoft:Windows:CurrentVersion:Policies:HKLM:Software:Microsoft:Windows:CurrentVersion:Policies:System
[snip]......
Some problems arise, the sed command is not working properly creating newlines. Second it removed a line that did not have the delimiter in the line. This isn't a huge deal, but means that I now have to manually line up the data. I now run a new sed command to replace the :HKLM with \nHKLM
sed -r "s/:HKLM/\\`echo -e '\nHKLM'`/g" regkeysonly > regkeysclean
OUTPUT:
HKLM:System:CurrentControlSet:Control:Lsa
HKLM:Software:Microsoft:Windows:CurrentVersion:Policies
HKLM:Software:Microsoft:Windows:CurrentVersion:Policies:System
[snip]......
I now replace the ":" with the "\" to get the data back to its original state
cat regkeysclean | tr ':' '\' > finished
OUTPUT:
HKLM\System\CurrentControlSet\Control\Lsa
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System
[snip]......
`
This works, but I think that if I could get the awk loop to use the "\" as the delimiter and the sed command to work this would be a two liner. Any thoughts?