<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to parse the events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-events/m-p/447434#M94653</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Type: VIP Status | Target: /Common/phutan.mayhem.com-80-int-llb | Status: The children pool member(s) either don't have service checking enabled, or service check results are not available yet | Current Conns: ;&lt;BR /&gt;
Type: VIP Status | Target: /Common/phutan.mayhem.com-443-int-llb | Status: The virtual server is available | Current Conns: ;&lt;BR /&gt;
Type: Pool Status | Target: /Common/phutan.mayhem.com-443-int-llb | Status: The pool is available | Current Conns: 902;&lt;BR /&gt;
Type: Pool Member Status | Target: 31.129.119.201:8443 | Status: Forced down | Current Conns: 0;&lt;BR /&gt;
Type: Pool Member Status | Target: 31.129.118.245:8343 | Status: Pool member is available | Current Conns: 213;&lt;BR /&gt;
Type: Pool Member Status | Target: 30.128.179.243:8343 | Status: Forced down | Current Conns: 0;&lt;BR /&gt;
Type: Pool Member Status | Target: 30.128.209.65:8343 | Status: Pool member is available | Current Conns: 211;&lt;BR /&gt;
Type: Pool Member Status | Target: 30.128.409.66:7443 | Status: Pool member is available | Current Conns: 216;&lt;BR /&gt;
Type: Pool Member Status | Target: 30.128.209.67:7343 | Status: Pool member is available | Current Conns: 247;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Above is how one of my sample events look like.&lt;BR /&gt;
I need help in parsing the events so that the output should look like in a table format like the following with four columns Target,Status,Current_Conns, Total_Connection   fetched from the event.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Target&lt;/STRONG&gt;                                  &lt;STRONG&gt;Status&lt;/STRONG&gt;                                     &lt;STRONG&gt;Current_Conns&lt;/STRONG&gt;      &lt;STRONG&gt;Total_Connection&lt;/STRONG&gt;&lt;BR /&gt;
31.129.119.201:8443        Forced down                             0                           902&lt;BR /&gt;
31.129.118.245:8343        Pool member is available      213&lt;BR /&gt;
30.128.179.243:8343        Pool member is available      0&lt;BR /&gt;
30.128.209.65:8343         Pool member is available      211&lt;BR /&gt;
30.128.409.66:7443         Pool member is available      216&lt;BR /&gt;
30.128.209.67:7343         Pool member is available      247 &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 19:55:17 GMT</pubDate>
    <dc:creator>zacksoft</dc:creator>
    <dc:date>2020-09-29T19:55:17Z</dc:date>
    <item>
      <title>How to parse the events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-events/m-p/447434#M94653</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Type: VIP Status | Target: /Common/phutan.mayhem.com-80-int-llb | Status: The children pool member(s) either don't have service checking enabled, or service check results are not available yet | Current Conns: ;&lt;BR /&gt;
Type: VIP Status | Target: /Common/phutan.mayhem.com-443-int-llb | Status: The virtual server is available | Current Conns: ;&lt;BR /&gt;
Type: Pool Status | Target: /Common/phutan.mayhem.com-443-int-llb | Status: The pool is available | Current Conns: 902;&lt;BR /&gt;
Type: Pool Member Status | Target: 31.129.119.201:8443 | Status: Forced down | Current Conns: 0;&lt;BR /&gt;
Type: Pool Member Status | Target: 31.129.118.245:8343 | Status: Pool member is available | Current Conns: 213;&lt;BR /&gt;
Type: Pool Member Status | Target: 30.128.179.243:8343 | Status: Forced down | Current Conns: 0;&lt;BR /&gt;
Type: Pool Member Status | Target: 30.128.209.65:8343 | Status: Pool member is available | Current Conns: 211;&lt;BR /&gt;
Type: Pool Member Status | Target: 30.128.409.66:7443 | Status: Pool member is available | Current Conns: 216;&lt;BR /&gt;
Type: Pool Member Status | Target: 30.128.209.67:7343 | Status: Pool member is available | Current Conns: 247;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Above is how one of my sample events look like.&lt;BR /&gt;
I need help in parsing the events so that the output should look like in a table format like the following with four columns Target,Status,Current_Conns, Total_Connection   fetched from the event.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Target&lt;/STRONG&gt;                                  &lt;STRONG&gt;Status&lt;/STRONG&gt;                                     &lt;STRONG&gt;Current_Conns&lt;/STRONG&gt;      &lt;STRONG&gt;Total_Connection&lt;/STRONG&gt;&lt;BR /&gt;
31.129.119.201:8443        Forced down                             0                           902&lt;BR /&gt;
31.129.118.245:8343        Pool member is available      213&lt;BR /&gt;
30.128.179.243:8343        Pool member is available      0&lt;BR /&gt;
30.128.209.65:8343         Pool member is available      211&lt;BR /&gt;
30.128.409.66:7443         Pool member is available      216&lt;BR /&gt;
30.128.209.67:7343         Pool member is available      247 &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:55:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-events/m-p/447434#M94653</guid>
      <dc:creator>zacksoft</dc:creator>
      <dc:date>2020-09-29T19:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse the events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-events/m-p/447435#M94654</link>
      <description>&lt;P&gt;try this out,&lt;BR /&gt;
&lt;CODE&gt;| extract pairdelim="|", kvdelim=":"&lt;/CODE&gt;&lt;BR /&gt;
did not test it yet ...&lt;BR /&gt;
or maybe use rex&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 12:15:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-events/m-p/447435#M94654</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-06-06T12:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse the events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-events/m-p/447436#M94655</link>
      <description>&lt;P&gt;Thanks, I'll try your suggestion.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 12:58:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-parse-the-events/m-p/447436#M94655</guid>
      <dc:creator>zacksoft</dc:creator>
      <dc:date>2018-06-06T12:58:50Z</dc:date>
    </item>
  </channel>
</rss>

