<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field Extraction from XML multiple Tag Elements [In Splunk Web - Index Time] in Security</title>
    <link>https://community.splunk.com/t5/Security/Field-Extraction-from-XML-multiple-Tag-Elements-In-Splunk-Web/m-p/453996#M10603</link>
    <description>&lt;P&gt;are you looking for index time or search time extraction?&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jul 2019 07:03:36 GMT</pubDate>
    <dc:creator>Sukisen1981</dc:creator>
    <dc:date>2019-07-03T07:03:36Z</dc:date>
    <item>
      <title>Field Extraction from XML multiple Tag Elements [In Splunk Web - Index Time]</title>
      <link>https://community.splunk.com/t5/Security/Field-Extraction-from-XML-multiple-Tag-Elements-In-Splunk-Web/m-p/453995#M10602</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have the following XML file containing many Objects elements.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version='1.0' encoding='UTF-8'?&amp;gt;
&amp;lt;Module name='ModuleName' ModuleAttributeName='/Path/To/ModuleName'&amp;gt;
    &amp;lt;ModuleAttribute name='IN_Scope' value='Project'/&amp;gt;
    &amp;lt;ModuleAttribute name='IN_Type' value='TRP'/&amp;gt;
    &amp;lt;ModuleAttribute name='IN_Feature' value='SYS'/&amp;gt;
    &amp;lt;ModuleAttribute name='IN_Area' value='SYSTEM'/&amp;gt;
    &amp;lt;ModuleAttribute name='ModuleType' value='TRP'/&amp;gt;
&amp;lt;Object id='11' MUID='MUID.11' GUID='110023er.11' &amp;gt;
    &amp;lt;Attribute name='State' value='ok'/&amp;gt;
    &amp;lt;Attribute name='evaluated' value='no'/&amp;gt;
    &amp;lt;Attribute name='original ASIL-Classification' value='---'/&amp;gt;
    &amp;lt;Attribute name='Source_CQ_ID' value=''/&amp;gt;
&amp;lt;/Object&amp;gt;
&amp;lt;Object id='12' MUID='MUID.12' GUID='110023er.12' &amp;gt;
    &amp;lt;Attribute name='State' value='ok'/&amp;gt;
    &amp;lt;Attribute name='evaluated' value='no'/&amp;gt;
    &amp;lt;Attribute name='original ASIL-Classification' value='---'/&amp;gt;
    &amp;lt;Attribute name='Source_CQ_ID' value=''/&amp;gt;
&amp;lt;/Object&amp;gt;&amp;lt;/Module&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;``&lt;/P&gt;

&lt;P&gt;I have liked to have the following structure:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Object
    - ModuleName: ModuleAttributeName
    - ModuleFullName: /Path/To/ModuleName
    - ModuleIN_Scope: Project
    - ModuleIN_Feature: TRP
    - ModuleAttributeWhatever: ...
    - ObjectState: ok
    - ObjectEvaluated: no
    - ObjectSource_CQ_ID: ''
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How can I easily parse this in splunk ? The Module Tag appeas&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 15:01:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Field-Extraction-from-XML-multiple-Tag-Elements-In-Splunk-Web/m-p/453995#M10602</guid>
      <dc:creator>dfofie</dc:creator>
      <dc:date>2019-07-02T15:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction from XML multiple Tag Elements [In Splunk Web - Index Time]</title>
      <link>https://community.splunk.com/t5/Security/Field-Extraction-from-XML-multiple-Tag-Elements-In-Splunk-Web/m-p/453996#M10603</link>
      <description>&lt;P&gt;are you looking for index time or search time extraction?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 07:03:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Field-Extraction-from-XML-multiple-Tag-Elements-In-Splunk-Web/m-p/453996#M10603</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2019-07-03T07:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Field Extraction from XML multiple Tag Elements [In Splunk Web - Index Time]</title>
      <link>https://community.splunk.com/t5/Security/Field-Extraction-from-XML-multiple-Tag-Elements-In-Splunk-Web/m-p/453997#M10604</link>
      <description>&lt;P&gt;Hello @sukissen, I'm mostly looking for the index time extraction.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 07:12:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Field-Extraction-from-XML-multiple-Tag-Elements-In-Splunk-Web/m-p/453997#M10604</guid>
      <dc:creator>dfofie</dc:creator>
      <dc:date>2019-07-03T07:12:35Z</dc:date>
    </item>
  </channel>
</rss>

