<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic is possible to index XML ? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/is-possible-to-index-XML/m-p/162675#M10008</link>
    <description>&lt;P&gt;is possible to index the XML pattern data into splunk and do Splunk search?&lt;/P&gt;

&lt;P&gt;In our case, we need to index the XML and co-relate the other logs using Splunk. Can you please suggest the best approach.&lt;/P&gt;

&lt;P&gt;Sample Data:&lt;/P&gt;

&lt;P&gt;&lt;LISTPERSONATTRIBUTES recordcount="717"&gt;&lt;BR /&gt;
    &lt;PERSONATTRIBUTE id="3"&gt;&lt;BR /&gt;
        &lt;NAME&gt;firstName&lt;/NAME&gt;&lt;BR /&gt;
        &lt;DESC&gt;firstName&lt;/DESC&gt;&lt;BR /&gt;
        &lt;ATTRIBUTETYPE&gt;STRING&lt;/ATTRIBUTETYPE&gt;&lt;BR /&gt;
        &lt;ISIMMUTABLE&gt;true&lt;/ISIMMUTABLE&gt;&lt;BR /&gt;
        &lt;CREATEDDATETIME&gt;2008-07-03 02:41:19.0&lt;/CREATEDDATETIME&gt;&lt;BR /&gt;
    &lt;/PERSONATTRIBUTE&gt;&lt;BR /&gt;
    &lt;PERSONATTRIBUTE id="4"&gt;&lt;BR /&gt;
        &lt;NAME&gt;lastName&lt;/NAME&gt;&lt;BR /&gt;
        &lt;DESC&gt;Last Name&lt;/DESC&gt;&lt;BR /&gt;
        &lt;ATTRIBUTETYPE&gt;STRING&lt;/ATTRIBUTETYPE&gt;&lt;BR /&gt;
        &lt;ISIMMUTABLE&gt;false&lt;/ISIMMUTABLE&gt;&lt;BR /&gt;
        &lt;CREATEDDATETIME&gt;2008-10-14 02:35:24.0&lt;/CREATEDDATETIME&gt;&lt;BR /&gt;
    &lt;/PERSONATTRIBUTE&gt;&lt;BR /&gt;
    &lt;PERSONATTRIBUTE id="6"&gt;&lt;BR /&gt;
        &lt;NAME&gt;middleName&lt;/NAME&gt;&lt;BR /&gt;
        &lt;DESC&gt;Middle Name&lt;/DESC&gt;&lt;BR /&gt;
        &lt;ATTRIBUTETYPE&gt;STRING&lt;/ATTRIBUTETYPE&gt;&lt;BR /&gt;
        &lt;ISIMMUTABLE&gt;true&lt;/ISIMMUTABLE&gt;&lt;BR /&gt;
        &lt;CREATEDDATETIME&gt;2007-11-30 01:12:55.0&lt;/CREATEDDATETIME&gt;&lt;BR /&gt;
    &lt;/PERSONATTRIBUTE&gt;&lt;BR /&gt;
    &lt;/LISTPERSONATTRIBUTES&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 13 May 2014 20:21:17 GMT</pubDate>
    <dc:creator>dhavamanis</dc:creator>
    <dc:date>2014-05-13T20:21:17Z</dc:date>
    <item>
      <title>is possible to index XML ?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/is-possible-to-index-XML/m-p/162675#M10008</link>
      <description>&lt;P&gt;is possible to index the XML pattern data into splunk and do Splunk search?&lt;/P&gt;

&lt;P&gt;In our case, we need to index the XML and co-relate the other logs using Splunk. Can you please suggest the best approach.&lt;/P&gt;

&lt;P&gt;Sample Data:&lt;/P&gt;

&lt;P&gt;&lt;LISTPERSONATTRIBUTES recordcount="717"&gt;&lt;BR /&gt;
    &lt;PERSONATTRIBUTE id="3"&gt;&lt;BR /&gt;
        &lt;NAME&gt;firstName&lt;/NAME&gt;&lt;BR /&gt;
        &lt;DESC&gt;firstName&lt;/DESC&gt;&lt;BR /&gt;
        &lt;ATTRIBUTETYPE&gt;STRING&lt;/ATTRIBUTETYPE&gt;&lt;BR /&gt;
        &lt;ISIMMUTABLE&gt;true&lt;/ISIMMUTABLE&gt;&lt;BR /&gt;
        &lt;CREATEDDATETIME&gt;2008-07-03 02:41:19.0&lt;/CREATEDDATETIME&gt;&lt;BR /&gt;
    &lt;/PERSONATTRIBUTE&gt;&lt;BR /&gt;
    &lt;PERSONATTRIBUTE id="4"&gt;&lt;BR /&gt;
        &lt;NAME&gt;lastName&lt;/NAME&gt;&lt;BR /&gt;
        &lt;DESC&gt;Last Name&lt;/DESC&gt;&lt;BR /&gt;
        &lt;ATTRIBUTETYPE&gt;STRING&lt;/ATTRIBUTETYPE&gt;&lt;BR /&gt;
        &lt;ISIMMUTABLE&gt;false&lt;/ISIMMUTABLE&gt;&lt;BR /&gt;
        &lt;CREATEDDATETIME&gt;2008-10-14 02:35:24.0&lt;/CREATEDDATETIME&gt;&lt;BR /&gt;
    &lt;/PERSONATTRIBUTE&gt;&lt;BR /&gt;
    &lt;PERSONATTRIBUTE id="6"&gt;&lt;BR /&gt;
        &lt;NAME&gt;middleName&lt;/NAME&gt;&lt;BR /&gt;
        &lt;DESC&gt;Middle Name&lt;/DESC&gt;&lt;BR /&gt;
        &lt;ATTRIBUTETYPE&gt;STRING&lt;/ATTRIBUTETYPE&gt;&lt;BR /&gt;
        &lt;ISIMMUTABLE&gt;true&lt;/ISIMMUTABLE&gt;&lt;BR /&gt;
        &lt;CREATEDDATETIME&gt;2007-11-30 01:12:55.0&lt;/CREATEDDATETIME&gt;&lt;BR /&gt;
    &lt;/PERSONATTRIBUTE&gt;&lt;BR /&gt;
    &lt;/LISTPERSONATTRIBUTES&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2014 20:21:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/is-possible-to-index-XML/m-p/162675#M10008</guid>
      <dc:creator>dhavamanis</dc:creator>
      <dc:date>2014-05-13T20:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: is possible to index XML ?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/is-possible-to-index-XML/m-p/162676#M10009</link>
      <description>&lt;P&gt;Yes indeed. Have look at the other post on similar lines.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/70619/parsing-xml-log-files" target="_blank"&gt;http://answers.splunk.com/answers/70619/parsing-xml-log-files&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/2141/xml-log-source-type" target="_blank"&gt;http://answers.splunk.com/answers/2141/xml-log-source-type&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/28619/indexing-xml-log-file-input" target="_blank"&gt;http://answers.splunk.com/answers/28619/indexing-xml-log-file-input&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Update:&lt;BR /&gt;
Try this (corrected regex and added MAX_DAYS_AGO to accommodate your older date values, increase more if you have timestamp older than then 4000 days( close to 12 years)&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[fastone]
BREAK_ONLY_BEFORE = (\&amp;lt;personattribute\sid|\&amp;lt;/listpersonattribute)
NO_BINARY_CHECK = 1
REPORT-xmlext = xml-extr
SHOULD_LINEMERGE = true
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3N
TIME_PREFIX = \&amp;lt;createddatetime\&amp;gt;
pulldown_type = 1
REPORT-xmlext = xml-extr
MAX_DAYS_AGO = 4000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[xml-extr] 
REGEX = \&amp;lt;(\w+)\&amp;gt;([^\&amp;gt;]*)\&amp;lt;/
FORMAT = $1::$2
MV_ADD = true
REPEAT_MATCH = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Regarding the date &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:36:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/is-possible-to-index-XML/m-p/162676#M10009</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-09-28T16:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: is possible to index XML ?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/is-possible-to-index-XML/m-p/162677#M10010</link>
      <description>&lt;P&gt;@somesoni2 - if you put answers in the Answers box, then good things can happen: first, you can get credit for your answers. Second, and much more important: other users will see this as an ANSWERED question and so they will look at if they need help. So you will be helping many more people. UNANSWERED questions (like this one) are ignored by people who are looking for answers.&lt;BR /&gt;
Please put answers in the Answers box!&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2014 21:26:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/is-possible-to-index-XML/m-p/162677#M10010</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-05-13T21:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: is possible to index XML ?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/is-possible-to-index-XML/m-p/162678#M10011</link>
      <description>&lt;P&gt;Thank you, i am getting this error for line breaking and also event date not extracting from the xml attribute "createdDateTime", &lt;/P&gt;

&lt;P&gt;Line breaking regex has no capturing groups: &amp;gt;\s*(?=&amp;lt;personAttribute&amp;gt;)&lt;/P&gt;

&lt;P&gt;We want to extract as a fields from each element in the xml. Can you please review the below,&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;BR /&gt;
[xml]&lt;BR /&gt;
LINE_BREAKER = &amp;gt;\s*(?=&amp;lt;personAttribute&amp;gt;)&lt;BR /&gt;
TIME_PREFIX = &amp;lt;createdDateTime&amp;gt;&lt;BR /&gt;
TIME_FORMAT = %Y-%m-%d %H:%M:%S.%3N&lt;BR /&gt;
SHOULD_LINEMERGE = true&lt;BR /&gt;
KV_MODE=xml&lt;BR /&gt;
REPORT-xmlext = xml-extr&lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[xml-extr]&lt;BR /&gt;
REGEX = &amp;lt;(w+)&amp;gt;([^&amp;lt;]*)&lt;BR /&gt;
FORMAT = $1::$2&lt;BR /&gt;
MV_ADD = true&lt;BR /&gt;
REPEAT_MATCH = true&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/is-possible-to-index-XML/m-p/162678#M10011</guid>
      <dc:creator>dhavamanis</dc:creator>
      <dc:date>2020-09-28T16:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: is possible to index XML ?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/is-possible-to-index-XML/m-p/162679#M10012</link>
      <description>&lt;P&gt;Try the updated answer.&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2014 19:18:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/is-possible-to-index-XML/m-p/162679#M10012</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-05-14T19:18:04Z</dc:date>
    </item>
  </channel>
</rss>

