<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: KV_Mode Splunk 6 not Working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/KV-Mode-Splunk-6-not-Working/m-p/80122#M16487</link>
    <description>&lt;P&gt;This had nothing to do with Splunk 6. I was missing the following in my &lt;CODE&gt;props.config&lt;/CODE&gt;. This was done in &lt;CODE&gt;etc/system/local/props.config&lt;/CODE&gt; at a global scope in our PROD configuration, but wasn't present in our DEV instance &lt;CODE&gt;apps/customApp/local/props.config&lt;/CODE&gt; local scope.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[customsourcetype]
BREAK_ONLY_BEFORE = ^&amp;lt;CustomEvent
SHOULD_LINEMERGE = true
MAX_TIMESTAMP_LOOKAHEAD=200
KV_MODE = xml
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 02 Oct 2013 21:30:05 GMT</pubDate>
    <dc:creator>slierninja</dc:creator>
    <dc:date>2013-10-02T21:30:05Z</dc:date>
    <item>
      <title>KV_Mode Splunk 6 not Working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/KV-Mode-Splunk-6-not-Working/m-p/80121#M16486</link>
      <description>&lt;P&gt;We have an XML log file that properly gets extracted in Splunk 5, but in Splunk 6 it doesn't properly identify the events. Events seem to be occurring at random in the search results - it doesn't seem to be honoring the KV_Mode. We get 5 events listed with only 2 XML events being sent. &lt;/P&gt;

&lt;H3&gt;Input XML (2 Events)&lt;/H3&gt;

&lt;P&gt;&amp;lt;CustomEvent&amp;gt;&lt;BR /&gt;
  &amp;lt;CreatedOn&amp;gt;2013-09-29T16:47:12&amp;lt;/CreatedOn&amp;gt;&lt;BR /&gt;
  &amp;lt;EventType&amp;gt;urn:mycustomevent&amp;lt;/EventType&amp;gt;&lt;BR /&gt;
  &amp;lt;Body&amp;gt;&lt;BR /&gt;
    &amp;lt;EventType2&amp;gt;action:login&amp;lt;/EventType2&amp;gt;&lt;BR /&gt;
    &amp;lt;EventDateTime&amp;gt;2013-09-29T16:47:12&amp;lt;/EventDateTime&amp;gt;&lt;BR /&gt;&lt;BR /&gt;
    &amp;lt;EventDetails /&amp;gt;&lt;BR /&gt;
  &amp;lt;/Body&amp;gt;&lt;BR /&gt;
&amp;lt;/CustomEvent&amp;gt;&lt;BR /&gt;
&amp;lt;CustomEvent&amp;gt;&lt;BR /&gt;
  &amp;lt;CreatedOn&amp;gt;2013-09-29T18:47:12&amp;lt;/CreatedOn&amp;gt;&lt;BR /&gt;
  &amp;lt;EventType&amp;gt;urn:mycustomevent&amp;lt;/EventType&amp;gt;&lt;BR /&gt;
  &amp;lt;Body&amp;gt;&lt;BR /&gt;
    &amp;lt;EventType2&amp;gt;action:logout&amp;lt;/EventType2&amp;gt;&lt;BR /&gt;
    &amp;lt;EventDateTime&amp;gt;2013-09-29T16:47:12&amp;lt;/EventDateTime&amp;gt;&lt;BR /&gt;&lt;BR /&gt;
    &amp;lt;EventDetails /&amp;gt;&lt;BR /&gt;
  &amp;lt;/Body&amp;gt;&lt;BR /&gt;
&amp;lt;/CustomEvent&amp;gt;&lt;/P&gt;

&lt;H3&gt;Output Events (5 Events)&lt;/H3&gt;

&lt;OL&gt;
&lt;LI&gt;&amp;lt;CustomEvent&amp;gt;&lt;/LI&gt;
&lt;LI&gt;&amp;lt;CreatedOn&amp;gt;2013-09-29T18:47:12&amp;lt;/CreatedOn&amp;gt;
&amp;lt;EventType&amp;gt;urn:mycustomevent&amp;lt;/EventType&amp;gt;
&amp;lt;Body&amp;gt;
&amp;lt;EventType2&amp;gt;action:logout&amp;lt;/EventType2&amp;gt;&lt;/LI&gt;
&lt;LI&gt;&amp;lt;EventDateTime&amp;gt;2013-09-29T16:47:12&amp;lt;/EventDateTime&amp;gt;&lt;BR /&gt;
&amp;lt;EventDetails /&amp;gt;
&amp;lt;/Body&amp;gt;
&amp;lt;/CustomEvent&amp;gt;&lt;/LI&gt;
&lt;LI&gt;&amp;lt;EventDateTime&amp;gt;2013-09-29T16:47:12&amp;lt;/EventDateTime&amp;gt;&lt;BR /&gt;
&amp;lt;EventDetails /&amp;gt;
&amp;lt;/Body&amp;gt;
&amp;lt;/CustomEvent&amp;gt;
&amp;lt;CustomEvent&amp;gt;&lt;/LI&gt;
&lt;LI&gt;&amp;lt;CreatedOn&amp;gt;2013-09-29T16:47:12&amp;lt;/CreatedOn&amp;gt;
&amp;lt;EventType&amp;gt;urn:mycustomevent&amp;lt;/EventType&amp;gt;
&amp;lt;Body&amp;gt;
&amp;lt;EventType2&amp;gt;action:login&amp;lt;/EventType2&amp;gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 02 Oct 2013 16:22:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/KV-Mode-Splunk-6-not-Working/m-p/80121#M16486</guid>
      <dc:creator>slierninja</dc:creator>
      <dc:date>2013-10-02T16:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: KV_Mode Splunk 6 not Working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/KV-Mode-Splunk-6-not-Working/m-p/80122#M16487</link>
      <description>&lt;P&gt;This had nothing to do with Splunk 6. I was missing the following in my &lt;CODE&gt;props.config&lt;/CODE&gt;. This was done in &lt;CODE&gt;etc/system/local/props.config&lt;/CODE&gt; at a global scope in our PROD configuration, but wasn't present in our DEV instance &lt;CODE&gt;apps/customApp/local/props.config&lt;/CODE&gt; local scope.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[customsourcetype]
BREAK_ONLY_BEFORE = ^&amp;lt;CustomEvent
SHOULD_LINEMERGE = true
MAX_TIMESTAMP_LOOKAHEAD=200
KV_MODE = xml
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 02 Oct 2013 21:30:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/KV-Mode-Splunk-6-not-Working/m-p/80122#M16487</guid>
      <dc:creator>slierninja</dc:creator>
      <dc:date>2013-10-02T21:30:05Z</dc:date>
    </item>
  </channel>
</rss>

