<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Define custom sourcetype XML in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Define-custom-sourcetype-XML/m-p/237727#M46184</link>
    <description>&lt;P&gt;Give this a try  (props.conf on Indexer/Heavy forwarder)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[yoursourcetype]
SHOULD_LINEMERGE=true
LINE_BREAKER=(\&amp;lt;\?xml[^\?]+\?\&amp;gt;)
TIME_PREFIX=Time\s*\&amp;gt;
TIME_FORMAT=%Y-%m-%dT%H:%M:%S.%N
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 08 Mar 2016 18:25:41 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2016-03-08T18:25:41Z</dc:date>
    <item>
      <title>Define custom sourcetype XML</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Define-custom-sourcetype-XML/m-p/237726#M46183</link>
      <description>&lt;P&gt;I'm trying to define a custom sourcetype. I have one file with multiple XML files.&lt;/P&gt;

&lt;P&gt;For example MyFile.xml:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version = '1.0' encoding = 'UTF-8' standalone = 'yes'?&amp;gt;&amp;lt;DATA&amp;gt;
   &amp;lt;Time&amp;gt;2016-02-12T00:00:00.211Z&amp;lt;/Time&amp;gt;
   &amp;lt;Item&amp;gt;
      &amp;lt;ID&amp;gt;1545454&amp;lt;/ID&amp;gt;
      &amp;lt;VAR1&amp;gt;897654564dDJUHFKHJHEU&amp;lt;/VAR1&amp;gt;
   &amp;lt;/Item&amp;gt;
   &amp;lt;Check&amp;gt;OK&amp;lt;/Check&amp;gt;
&amp;lt;/DATA&amp;gt;
&amp;lt;?xml version = '1.0' encoding = 'UTF-8' standalone = 'yes'?&amp;gt;&amp;lt;DATA&amp;gt;
   &amp;lt;Time&amp;gt;2016-02-12T00:00:00.211Z&amp;lt;/Time&amp;gt;
   &amp;lt;Item&amp;gt;
      &amp;lt;ID&amp;gt;456849836848&amp;lt;/ID&amp;gt;
      &amp;lt;VAR5&amp;gt;78964DFDFli_DFDFD_DFDF&amp;lt;/VAR5&amp;gt;
   &amp;lt;/Item&amp;gt;
   &amp;lt;Check&amp;gt;FAILD&amp;lt;/Check&amp;gt;
&amp;lt;/DATA&amp;gt;
&amp;lt;?xml version = '1.0' encoding = 'UTF-8'?&amp;gt;&amp;lt;LOG&amp;gt;
   &amp;lt;Send&amp;gt;FKK_64646464&amp;lt;/Send&amp;gt;
   &amp;lt;TimestampSend&amp;gt;2016-02-08T04:44:53.417Z&amp;lt;/TimestampSend&amp;gt;
   &amp;lt;By&amp;gt;MFF_5687654&amp;lt;/By&amp;gt;
   &amp;lt;MessageId&amp;gt;Title Test&amp;lt;/MessageId&amp;gt;
   &amp;lt;Message&amp;gt;
      &amp;lt;Resp&amp;gt;
         &amp;lt;EventTime&amp;gt;2016-02-08T04:44:53.418Z&amp;lt;/EventTime&amp;gt;
         &amp;lt;Info&amp;gt;
            &amp;lt;Item&amp;gt;
               &amp;lt;Id&amp;gt;INFO_222&amp;lt;/Id&amp;gt;
            &amp;lt;/Item&amp;gt;
            &amp;lt;Description&amp;gt;
               &amp;lt;Id&amp;gt;BCC_456&amp;lt;/Id&amp;gt;
               &amp;lt;ByID&amp;gt;45&amp;lt;/ByID&amp;gt;
            &amp;lt;/Description&amp;gt;
         &amp;lt;/Info&amp;gt;
         &amp;lt;Status&amp;gt;404&amp;lt;/Status&amp;gt;
      &amp;lt;/Resp&amp;gt;
   &amp;lt;/Message&amp;gt;
&amp;lt;/LOG&amp;gt;
&amp;lt;?xml version = '1.0' encoding = 'UTF-8' standalone = 'yes'?&amp;gt;&amp;lt;DATA&amp;gt;
   &amp;lt;Time&amp;gt;2016-02-12T00:00:00.211Z&amp;lt;/Time&amp;gt;
   &amp;lt;Item&amp;gt;
      &amp;lt;ID&amp;gt;45454545&amp;lt;/ID&amp;gt;
      &amp;lt;VAR88&amp;gt;LJDKI_DFDFDF_DFDFDF_EJRHUHEJK&amp;lt;/VAR88&amp;gt;
   &amp;lt;/Item&amp;gt;
   &amp;lt;Check&amp;gt;WARNING&amp;lt;/Check&amp;gt;
&amp;lt;/DATA&amp;gt;
&amp;lt;?xml version = '1.0' encoding = 'UTF-8'?&amp;gt;&amp;lt;LOG&amp;gt;
   &amp;lt;Send&amp;gt;FKK_64646465&amp;lt;/Send&amp;gt;
   &amp;lt;TimestampSend&amp;gt;2016-02-08T04:48:53.417Z&amp;lt;/TimestampSend&amp;gt;
   &amp;lt;By&amp;gt;MFF_5687655&amp;lt;/By&amp;gt;
   &amp;lt;MessageId&amp;gt;Title Test&amp;lt;/MessageId&amp;gt;
   &amp;lt;Message&amp;gt;
      &amp;lt;Resp&amp;gt;
         &amp;lt;EventTime&amp;gt;2016-02-08T04:48:53.418Z&amp;lt;/EventTime&amp;gt;
         &amp;lt;Info&amp;gt;
            &amp;lt;Item&amp;gt;
               &amp;lt;Id&amp;gt;INFO_223&amp;lt;/Id&amp;gt;
            &amp;lt;/Item&amp;gt;
            &amp;lt;Description&amp;gt;
               &amp;lt;Id&amp;gt;BCC_457&amp;lt;/Id&amp;gt;
               &amp;lt;ByID&amp;gt;46&amp;lt;/ByID&amp;gt;
            &amp;lt;/Description&amp;gt;
         &amp;lt;/Info&amp;gt;
         &amp;lt;Status&amp;gt;404&amp;lt;/Status&amp;gt;
      &amp;lt;/Resp&amp;gt;
   &amp;lt;/Message&amp;gt;
&amp;lt;/LOG&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;My props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mysourcetype]
 DATETIME_CONFIG = CURRENT
 KV_MODE = xml
 LINE_BREAKER = (&amp;lt;?xml)
 NO_BINARY_CHECK = 1
 SHOULD_LINEMERGE = false
 TRUNCATE = 0
 pulldown_type = 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How can I set the LINE_BREAKER by "&amp;lt;?xml version = '1.0' encoding = 'UTF-8' standalone = 'yes'?&amp;gt;"&lt;BR /&gt;
Is there a way te set the DATETIME to  or  with regex?&lt;BR /&gt;
What did I do wrong?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 11:56:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Define-custom-sourcetype-XML/m-p/237726#M46183</guid>
      <dc:creator>raymondc</dc:creator>
      <dc:date>2016-03-08T11:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Define custom sourcetype XML</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Define-custom-sourcetype-XML/m-p/237727#M46184</link>
      <description>&lt;P&gt;Give this a try  (props.conf on Indexer/Heavy forwarder)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[yoursourcetype]
SHOULD_LINEMERGE=true
LINE_BREAKER=(\&amp;lt;\?xml[^\?]+\?\&amp;gt;)
TIME_PREFIX=Time\s*\&amp;gt;
TIME_FORMAT=%Y-%m-%dT%H:%M:%S.%N
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 08 Mar 2016 18:25:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Define-custom-sourcetype-XML/m-p/237727#M46184</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-03-08T18:25:41Z</dc:date>
    </item>
  </channel>
</rss>

