<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic We are trying to make a REST input and the result is XML data but it has no schema. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/We-are-trying-to-make-a-REST-input-and-the-result-is-XML-data/m-p/306918#M93040</link>
    <description>&lt;P&gt;We are trying to make a REST input and the result is XML data but it has no schema. The Source we are using is the Palo Alto, specifically Panorama, not the firewalls directly. Can someone help me create an XML schema??? (I have been stuck on this for a while!) Is there a way to manually build a schema in splunk for this input?&lt;/P&gt;</description>
    <pubDate>Fri, 31 Mar 2017 00:50:51 GMT</pubDate>
    <dc:creator>rshoun</dc:creator>
    <dc:date>2017-03-31T00:50:51Z</dc:date>
    <item>
      <title>We are trying to make a REST input and the result is XML data but it has no schema.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/We-are-trying-to-make-a-REST-input-and-the-result-is-XML-data/m-p/306918#M93040</link>
      <description>&lt;P&gt;We are trying to make a REST input and the result is XML data but it has no schema. The Source we are using is the Palo Alto, specifically Panorama, not the firewalls directly. Can someone help me create an XML schema??? (I have been stuck on this for a while!) Is there a way to manually build a schema in splunk for this input?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 00:50:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/We-are-trying-to-make-a-REST-input-and-the-result-is-XML-data/m-p/306918#M93040</guid>
      <dc:creator>rshoun</dc:creator>
      <dc:date>2017-03-31T00:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: We are trying to make a REST input and the result is XML data but it has no schema.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/We-are-trying-to-make-a-REST-input-and-the-result-is-XML-data/m-p/306919#M93041</link>
      <description>&lt;P&gt;Well, without a sample log it won't be easy to help you. &lt;/P&gt;

&lt;P&gt;Did you try with : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;KVMODE = xml 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 31 Mar 2017 08:52:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/We-are-trying-to-make-a-REST-input-and-the-result-is-XML-data/m-p/306919#M93041</guid>
      <dc:creator>3no</dc:creator>
      <dc:date>2017-03-31T08:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: We are trying to make a REST input and the result is XML data but it has no schema.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/We-are-trying-to-make-a-REST-input-and-the-result-is-XML-data/m-p/306920#M93042</link>
      <description>&lt;P&gt;Actually, &lt;CODE&gt;KV_MODE = xml&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 21:40:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/We-are-trying-to-make-a-REST-input-and-the-result-is-XML-data/m-p/306920#M93042</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-03-31T21:40:30Z</dc:date>
    </item>
  </channel>
</rss>

