<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XML fields and multivalues in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14797#M1555</link>
    <description>&lt;P&gt;Sounds like you want "chart count over scap_id by name"&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jul 2010 13:38:57 GMT</pubDate>
    <dc:creator>sideview</dc:creator>
    <dc:date>2010-07-01T13:38:57Z</dc:date>
    <item>
      <title>XML fields and multivalues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14793#M1551</link>
      <description>&lt;P&gt;I am trying to search on the name field by scap-id in the following data. When I search against it Splunk returns one value for the name and throws out the rest. How do I make name a multivalued field. I have included a dataset and my props.conf and transforms.conf.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;controls scap-id='CVE-2010-1241'&amp;gt;
    &amp;lt;control internal-id='8081023'&amp;gt;
      &amp;lt;name&amp;gt;Updates for Windows Applications::Adobe Reader 8.2.2 Available - Adobe Reader 8.2.1&amp;lt;/name&amp;gt;
      &amp;lt;release-date&amp;gt;Tue, 13 Apr 2010&amp;lt;/release-date&amp;gt;
      &amp;lt;statistics&amp;gt;
        &amp;lt;scanned&amp;gt;4&amp;lt;/scanned&amp;gt;
        &amp;lt;passed&amp;gt;4&amp;lt;/passed&amp;gt;
        &amp;lt;failed&amp;gt;0&amp;lt;/failed&amp;gt;
        &amp;lt;patched&amp;gt;0&amp;lt;/patched&amp;gt;
        &amp;lt;mean-patch-time-hours&amp;gt;NaN&amp;lt;/mean-patch-time-hours&amp;gt;
      &amp;lt;/statistics&amp;gt;
      &amp;lt;exceptions&amp;gt;
        &amp;lt;has-exception&amp;gt;false&amp;lt;/has-exception&amp;gt;
        &amp;lt;use-exception&amp;gt;true&amp;lt;/use-exception&amp;gt;
        &amp;lt;exempt-count&amp;gt;0&amp;lt;/exempt-count&amp;gt;
      &amp;lt;/exceptions&amp;gt;
    &amp;lt;/control&amp;gt;
    &amp;lt;control internal-id='8081024'&amp;gt;
      &amp;lt;name&amp;gt;Updates for Windows Applications::Adobe Reader 8.2.2 Available - Adobe Reader 8.2.1 (French)&amp;lt;/name&amp;gt;
      &amp;lt;release-date&amp;gt;Tue, 13 Apr 2010&amp;lt;/release-date&amp;gt;
      &amp;lt;statistics&amp;gt;
        &amp;lt;scanned&amp;gt;4&amp;lt;/scanned&amp;gt;
        &amp;lt;passed&amp;gt;4&amp;lt;/passed&amp;gt;
        &amp;lt;failed&amp;gt;0&amp;lt;/failed&amp;gt;
        &amp;lt;patched&amp;gt;0&amp;lt;/patched&amp;gt;
        &amp;lt;mean-patch-time-hours&amp;gt;NaN&amp;lt;/mean-patch-time-hours&amp;gt;
      &amp;lt;/statistics&amp;gt;
      &amp;lt;exceptions&amp;gt;
        &amp;lt;has-exception&amp;gt;false&amp;lt;/has-exception&amp;gt;
        &amp;lt;use-exception&amp;gt;true&amp;lt;/use-exception&amp;gt;
        &amp;lt;exempt-count&amp;gt;0&amp;lt;/exempt-count&amp;gt;
      &amp;lt;/exceptions&amp;gt;
    &amp;lt;/control&amp;gt;
    &amp;lt;control internal-id='8091029'&amp;gt;
      &amp;lt;name&amp;gt;Updates for Windows Applications::Adobe Reader 9.3.2 Available - Adobe Reader 9.3/9.3.1&amp;lt;/name&amp;gt;
      &amp;lt;release-date&amp;gt;Tue, 13 Apr 2010&amp;lt;/release-date&amp;gt;
      &amp;lt;statistics&amp;gt;
        &amp;lt;scanned&amp;gt;4&amp;lt;/scanned&amp;gt;
        &amp;lt;passed&amp;gt;3&amp;lt;/passed&amp;gt;
        &amp;lt;failed&amp;gt;1&amp;lt;/failed&amp;gt;
        &amp;lt;patched&amp;gt;0&amp;lt;/patched&amp;gt;
        &amp;lt;mean-patch-time-hours&amp;gt;NaN&amp;lt;/mean-patch-time-hours&amp;gt;
      &amp;lt;/statistics&amp;gt;
      &amp;lt;exceptions&amp;gt;
        &amp;lt;has-exception&amp;gt;false&amp;lt;/has-exception&amp;gt;
        &amp;lt;use-exception&amp;gt;true&amp;lt;/use-exception&amp;gt;
        &amp;lt;exempt-count&amp;gt;0&amp;lt;/exempt-count&amp;gt;
      &amp;lt;/exceptions&amp;gt;
    &amp;lt;/control&amp;gt;
    &amp;lt;control internal-id='8091030'&amp;gt;
      &amp;lt;name&amp;gt;Updates for Windows Applications::Adobe Reader 9.3.2 Available - Adobe Reader 9.3/9.3.1 (French)&amp;lt;/name&amp;gt;
      &amp;lt;release-date&amp;gt;Tue, 13 Apr 2010&amp;lt;/release-date&amp;gt;
      &amp;lt;statistics&amp;gt;
        &amp;lt;scanned&amp;gt;4&amp;lt;/scanned&amp;gt;
        &amp;lt;passed&amp;gt;4&amp;lt;/passed&amp;gt;
        &amp;lt;failed&amp;gt;0&amp;lt;/failed&amp;gt;
        &amp;lt;patched&amp;gt;0&amp;lt;/patched&amp;gt;
        &amp;lt;mean-patch-time-hours&amp;gt;NaN&amp;lt;/mean-patch-time-hours&amp;gt;
      &amp;lt;/statistics&amp;gt;
      &amp;lt;exceptions&amp;gt;
        &amp;lt;has-exception&amp;gt;false&amp;lt;/has-exception&amp;gt;
        &amp;lt;use-exception&amp;gt;true&amp;lt;/use-exception&amp;gt;
        &amp;lt;exempt-count&amp;gt;0&amp;lt;/exempt-count&amp;gt;
      &amp;lt;/exceptions&amp;gt;
    &amp;lt;/control&amp;gt;
    &amp;lt;control internal-id='9081021'&amp;gt;
      &amp;lt;name&amp;gt;Updates for Windows Applications::Adobe Acrobat 8.2.2 Available - Adobe Acrobat 8.2/8.2.1&amp;lt;/name&amp;gt;
      &amp;lt;release-date&amp;gt;Tue, 13 Apr 2010&amp;lt;/release-date&amp;gt;
      &amp;lt;statistics&amp;gt;
        &amp;lt;scanned&amp;gt;4&amp;lt;/scanned&amp;gt;
        &amp;lt;passed&amp;gt;4&amp;lt;/passed&amp;gt;
        &amp;lt;failed&amp;gt;0&amp;lt;/failed&amp;gt;
        &amp;lt;patched&amp;gt;0&amp;lt;/patched&amp;gt;
        &amp;lt;mean-patch-time-hours&amp;gt;NaN&amp;lt;/mean-patch-time-hours&amp;gt;
      &amp;lt;/statistics&amp;gt;
      &amp;lt;exceptions&amp;gt;
        &amp;lt;has-exception&amp;gt;false&amp;lt;/has-exception&amp;gt;
        &amp;lt;use-exception&amp;gt;true&amp;lt;/use-exception&amp;gt;
        &amp;lt;exempt-count&amp;gt;0&amp;lt;/exempt-count&amp;gt;
      &amp;lt;/exceptions&amp;gt;
    &amp;lt;/control&amp;gt;
    &amp;lt;control internal-id='9081022'&amp;gt;
      &amp;lt;name&amp;gt;Updates for Windows Applications::Adobe Acrobat 8.2.2 Available - Adobe Acrobat 8.2/8.2.1 (French)&amp;lt;/name&amp;gt;
      &amp;lt;release-date&amp;gt;Tue, 13 Apr 2010&amp;lt;/release-date&amp;gt;
      &amp;lt;statistics&amp;gt;
        &amp;lt;scanned&amp;gt;4&amp;lt;/scanned&amp;gt;
        &amp;lt;passed&amp;gt;4&amp;lt;/passed&amp;gt;
        &amp;lt;failed&amp;gt;0&amp;lt;/failed&amp;gt;
        &amp;lt;patched&amp;gt;0&amp;lt;/patched&amp;gt;
        &amp;lt;mean-patch-time-hours&amp;gt;NaN&amp;lt;/mean-patch-time-hours&amp;gt;
      &amp;lt;/statistics&amp;gt;
      &amp;lt;exceptions&amp;gt;
        &amp;lt;has-exception&amp;gt;false&amp;lt;/has-exception&amp;gt;
        &amp;lt;use-exception&amp;gt;true&amp;lt;/use-exception&amp;gt;
        &amp;lt;exempt-count&amp;gt;0&amp;lt;/exempt-count&amp;gt;
      &amp;lt;/exceptions&amp;gt;
    &amp;lt;/control&amp;gt;
    &amp;lt;control internal-id='9091019'&amp;gt;
      &amp;lt;name&amp;gt;Updates for Windows Applications::Adobe Acrobat 9.3.2 Available - Adobe Acrobat 9.3/9.3.1&amp;lt;/name&amp;gt;
      &amp;lt;release-date&amp;gt;Tue, 13 Apr 2010&amp;lt;/release-date&amp;gt;
      &amp;lt;statistics&amp;gt;
        &amp;lt;scanned&amp;gt;4&amp;lt;/scanned&amp;gt;
        &amp;lt;passed&amp;gt;4&amp;lt;/passed&amp;gt;
        &amp;lt;failed&amp;gt;0&amp;lt;/failed&amp;gt;
        &amp;lt;patched&amp;gt;0&amp;lt;/patched&amp;gt;
        &amp;lt;mean-patch-time-hours&amp;gt;NaN&amp;lt;/mean-patch-time-hours&amp;gt;
      &amp;lt;/statistics&amp;gt;
      &amp;lt;exceptions&amp;gt;
        &amp;lt;has-exception&amp;gt;false&amp;lt;/has-exception&amp;gt;
        &amp;lt;use-exception&amp;gt;true&amp;lt;/use-exception&amp;gt;
        &amp;lt;exempt-count&amp;gt;0&amp;lt;/exempt-count&amp;gt;
      &amp;lt;/exceptions&amp;gt;
    &amp;lt;/control&amp;gt;
    &amp;lt;control internal-id='9091020'&amp;gt;
      &amp;lt;name&amp;gt;Updates for Windows Applications::Adobe Acrobat 9.3.2 Available - Adobe Acrobat 9.3/9.3.1 (French)&amp;lt;/name&amp;gt;
      &amp;lt;release-date&amp;gt;Tue, 13 Apr 2010&amp;lt;/release-date&amp;gt;
      &amp;lt;statistics&amp;gt;
        &amp;lt;scanned&amp;gt;4&amp;lt;/scanned&amp;gt;
        &amp;lt;passed&amp;gt;4&amp;lt;/passed&amp;gt;
        &amp;lt;failed&amp;gt;0&amp;lt;/failed&amp;gt;
        &amp;lt;patched&amp;gt;0&amp;lt;/patched&amp;gt;
        &amp;lt;mean-patch-time-hours&amp;gt;NaN&amp;lt;/mean-patch-time-hours&amp;gt;
      &amp;lt;/statistics&amp;gt;
      &amp;lt;exceptions&amp;gt;
        &amp;lt;has-exception&amp;gt;false&amp;lt;/has-exception&amp;gt;
        &amp;lt;use-exception&amp;gt;true&amp;lt;/use-exception&amp;gt;
        &amp;lt;exempt-count&amp;gt;0&amp;lt;/exempt-count&amp;gt;
      &amp;lt;/exceptions&amp;gt;
    &amp;lt;/control&amp;gt;
  &amp;lt;/controls&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[bigfix]
#TIME_PREFIX = &amp;lt;Extended_Timestamp&amp;gt;
#MAX_TIMESTAMP_LOOKAHEAD = 200
#MUST_BREAK_AFTER = &amp;lt;/controls&amp;gt;
#BREAK_ONLY_BEFORE_DATE = false
#SHOULD_LINEMERGE = true
#LINE_BREAKER = \&amp;gt;\s*(?=\&amp;lt;control\&amp;gt;)
BREAK_ONLY_BEFORE = &amp;lt;controls\sscap-id
REPORT-bigfix = xml-bigfix
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[xml-bigfix]
MV_ADD = true
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 03 Jun 2010 07:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14793#M1551</guid>
      <dc:creator>tjohnston2</dc:creator>
      <dc:date>2010-06-03T07:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: XML fields and multivalues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14794#M1552</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;[xml-bigfix]
REGEX = /&amp;lt;name(?:\s[^\&amp;gt;]*)?/&amp;gt;([^\&amp;lt;]*)\&amp;lt;\/name
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 03 Jun 2010 07:46:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14794#M1552</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-06-03T07:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: XML fields and multivalues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14795#M1553</link>
      <description>&lt;P&gt;Thanks  I would now like a tabular report which looks like this&lt;/P&gt;

&lt;P&gt;scap_id&lt;BR /&gt;
  name&lt;BR /&gt;
  name&lt;BR /&gt;
  name&lt;BR /&gt;
  etc...&lt;/P&gt;

&lt;P&gt;I can't seem to figure it out. I have tried stats list(name) by scap_id, stats values(name) by scap_id.  Help&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:13:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14795#M1553</guid>
      <dc:creator>tjohnston2</dc:creator>
      <dc:date>2020-09-28T09:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: XML fields and multivalues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14796#M1554</link>
      <description>&lt;P&gt;Thanks I would now like a tabular report which looks like this scap_id name name name etc... I can't seem to figure it out. I have tried stats list(name) by scap_id, stats values(name) by scap_id. Help&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:13:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14796#M1554</guid>
      <dc:creator>tjohnston2</dc:creator>
      <dc:date>2020-09-28T09:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: XML fields and multivalues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14797#M1555</link>
      <description>&lt;P&gt;Sounds like you want "chart count over scap_id by name"&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2010 13:38:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14797#M1555</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2010-07-01T13:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: XML fields and multivalues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14798#M1556</link>
      <description>&lt;P&gt;If you don't mind having many lines for each sscap-id: first expand the multivalued field to multiple events, then use table: "... | mvexpand name | table _time scap-id name"&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2010 15:31:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14798#M1556</guid>
      <dc:creator>Paolo_Prigione</dc:creator>
      <dc:date>2010-07-15T15:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: XML fields and multivalues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14799#M1557</link>
      <description>&lt;P&gt;Can you verify this works??
My transforms.conf looks like this&lt;/P&gt;

&lt;P&gt;[xmlkv_multivalue]
REGEX = &amp;lt;(.&lt;EM&gt;?)(?:\s[^&amp;gt;]&lt;/EM&gt;)?&amp;gt;([^&amp;lt;]*)
FORMAT = $1::$2
MV_ADD = true&lt;/P&gt;

&lt;P&gt;[xml_bigfix]
REGEX = /]&lt;EM&gt;)?/&amp;gt;([^\&amp;lt;]&lt;/EM&gt;)\&amp;lt;\/name&lt;/P&gt;

&lt;P&gt;and when I search I pipe to either on  the search line and get only one value per xml pair not multiples as advertised...&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2011 07:42:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/XML-fields-and-multivalues/m-p/14799#M1557</guid>
      <dc:creator>mjyates</dc:creator>
      <dc:date>2011-02-02T07:42:13Z</dc:date>
    </item>
  </channel>
</rss>

