<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XML multi-value help in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-multi-value-help/m-p/27964#M1118</link>
    <description>&lt;P&gt;I am new to Splunk and have been reading as much as I can, but I cannot figure this out. Trying to wrap my head around regex.  I have some xml data as below.  Splunk only identifies the first values of bi, o, pb, pool, amt, mode.  I need to work with each of these.  Would you please help me make these multi-valued? Thank you.&lt;BR /&gt;
&amp;#3;&lt;/P&gt;

&lt;P&gt;Board 3  Msg #  90962   19-JAN-2013  12:45:34.51   msg length = 871&lt;BR /&gt;
&amp;#2;&lt;BR /&gt;
&lt;MSG&gt;&lt;BR /&gt;
&lt;HEADER recid="WO" meet="GULFSTREAM" race="07" perf="0036" nvid="019" ivr="19" tra1="GPM" tra2="GP  M" card="8" sesno="344" sesdate="2013-01-19" racedate="2013-01-19" ptyp="   $"&gt;&lt;/HEADER&gt;&lt;BR /&gt;
&lt;WO_DATA date="2013-01-19" time="12:45:34" post="12:38:00" trackc="SLOPPY" turfc="YIELDING" typ="F" total="0.00"&gt;&lt;BR /&gt;
&lt;ODDSDATA&gt;&lt;BR /&gt;
 &lt;ENTRY bi="1" o="5/2" pb="3.90"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="2" o=" 60" pb="64.40"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="3" o="  4" pb="5.30"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="4" o="6/5" pb="2.20"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="5" o="  4" pb="5.40"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="6" o=" 17" pb="18.10"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="7" o=" 15" pb="16.10"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
&lt;/ODDSDATA&gt;&lt;BR /&gt;
&lt;FEATURE&gt; &lt;BR /&gt;
 &lt;TOTAL pool="EX " amt="238035.59" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
 &lt;TOTAL pool="TRI" amt="135852.36" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
 &lt;TOTAL pool="DD " amt="40299.99" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
 &lt;TOTAL pool="P03" amt="45939.06" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
 &lt;TOTAL pool="P05" amt="181860.94" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
 &lt;TOTAL pool="SPR" amt="77642.62" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
&lt;/FEATURE&gt; &lt;BR /&gt;
&lt;/WO_DATA&gt;&lt;BR /&gt;
&lt;/MSG&gt;&lt;/P&gt;

&lt;P&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/P&gt;

&lt;P&gt;Sorry for the delayed response.  Thank you both for trying to help, it is greatly appreciated.  There are more issues with my data than I thought.  I was working with a friend who has more experience with Splunk and he helped me get a decent start.  Unfortunately, now I have issues with line breaking.  I am trying to index the above type messages from a txt file.  In the txt file it it looks like.&lt;/P&gt;

&lt;P&gt;Board 3 &lt;EM&gt;stuff&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;XML &lt;EM&gt;stuff&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Board 3 &lt;EM&gt;stuff&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;XML &lt;EM&gt;stuff&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Where each event is within one line separated by the "Board 3..." stuff.  He helped me over come this using the following props.conf:&lt;/P&gt;

&lt;P&gt;[horsexml]&lt;BR /&gt;
#TIME_PREFIX = Board\s\d+\s+\w+\s#\s+\d+\s+&lt;BR /&gt;
#TIME_FORMAT = %d-%b-%Y  %H:%M:%S.%2N&lt;BR /&gt;
LINE_BREAKER = (Board[\s\d\w#-:=\]+)|(\x3)&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
KV_MODE = xml&lt;BR /&gt;
#REPORT-xmlext = xml-extr&lt;/P&gt;

&lt;P&gt;Unfortunately, there exist "returns" within each line begun with &lt;MSG&gt; after 133 characters.  So instead of one straight line of xml code Splunk sees something like this&lt;/MSG&gt;&lt;/P&gt;

&lt;P&gt;&amp;#3;&lt;/P&gt;

&lt;P&gt;&amp;#3;&lt;/P&gt;

&lt;P&gt;Board 3  Msg #  24830   19-JAN-2013  08:47:01.13   msg length = 855&lt;BR /&gt;
&amp;#2;&lt;BR /&gt;
&lt;MSG&gt;&lt;HEADER recid="WO" meet="GULFSTREAM" race="01" perf="0036" nvid="019" ivr="19" tra1="GPM" tra2="GP  M" card="8" sesno="344"&gt;&lt;BR /&gt;
SesDate="2013-01-19" RaceDate="2013-01-19" PTyp="   $" /&amp;gt;&lt;WO_DATA date="2013-01-19" time="08:47:01" post="09:45:00" trackc="SLOPPY"&gt;&lt;BR /&gt;
turfC="YIELDING" typ="A" Total="0.00"&amp;gt;&lt;ODDSDATA&gt;&lt;ENTRY bi="1" o=" 40" pb="42.40"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="2" o=" 80" pb="82.30"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="3"&gt;&lt;BR /&gt;
o=" 30" pb="35.40" /&amp;gt;&lt;ENTRY bi="4" o=" 50" pb="56.70"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="5" o=" 99" pb="124.20"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="6" o="1/9" pb="1.10"&gt;&lt;/ENTRY&gt;&lt;ENTRY&gt;&lt;BR /&gt;
 bi="7" o="  5" pb="6.50" /&amp;gt;&lt;ENTRY bi="8" o=" 15" pb="16.80"&gt;&lt;/ENTRY&gt;&lt;/ENTRY&gt;&lt;FEATURE&gt; &lt;TOTAL pool="EX " amt="2055.74" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTA&gt;&lt;BR /&gt;
l pool="TRI" amt="937.58" mode="N" /&amp;gt;&lt;TOTAL pool="DD " amt="2624.10" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTAL pool="P03" amt="2033.60" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTAL po=""&gt;&lt;BR /&gt;
ol="SPR" amt="800.76" mode="N" /&amp;gt;&lt;/TOTAL&gt; &lt;/TOTA&gt;&lt;/FEATURE&gt;&lt;BR /&gt;
&amp;#3;&lt;/ENTRY&gt;&lt;/ODDSDATA&gt;&lt;/WO_DATA&gt;&lt;/HEADER&gt;&lt;/MSG&gt;&lt;/P&gt;

&lt;P&gt;Board 3  Msg #  24944   19-JAN-2013  08:47:36.09   msg length = 855&lt;BR /&gt;
&amp;#2;&lt;BR /&gt;
&lt;MSG&gt;&lt;HEADER recid="WO" meet="GULFSTREAM" race="01" perf="0036" nvid="019" ivr="19" tra1="GPM" tra2="GP  M" card="8" sesno="344"&gt;&lt;BR /&gt;
SesDate="2013-01-19" RaceDate="2013-01-19" PTyp="   $" /&amp;gt;&lt;WO_DATA date="2013-01-19" time="08:47:36" post="09:45:00" trackc="SLOPPY"&gt;&lt;BR /&gt;
turfC="YIELDING" typ="A" Total="0.00"&amp;gt;&lt;ODDSDATA&gt;&lt;ENTRY bi="1" o=" 40" pb="41.50"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="2" o=" 80" pb="81.60"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="3"&gt;&lt;BR /&gt;
o=" 30" pb="35.50" /&amp;gt;&lt;ENTRY bi="4" o=" 50" pb="57.00"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="5" o=" 99" pb="122.40"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="6" o="1/9" pb="1.10"&gt;&lt;/ENTRY&gt;&lt;ENTRY&gt;&lt;BR /&gt;
 bi="7" o="  5" pb="6.40" /&amp;gt;&lt;ENTRY bi="8" o=" 15" pb="16.90"&gt;&lt;/ENTRY&gt;&lt;/ENTRY&gt;&lt;FEATURE&gt; &lt;TOTAL pool="EX " amt="2077.34" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTA&gt;&lt;BR /&gt;
l pool="TRI" amt="949.05" mode="N" /&amp;gt;&lt;TOTAL pool="DD " amt="2708.90" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTAL pool="P03" amt="2033.50" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTAL po=""&gt;&lt;BR /&gt;
ol="SPR" amt="808.82" mode="N" /&amp;gt;&lt;/TOTAL&gt; &lt;/TOTA&gt;&lt;/FEATURE&gt;&lt;/ENTRY&gt;&lt;/ODDSDATA&gt;&lt;/WO_DATA&gt;&lt;/HEADER&gt;&lt;/MSG&gt;&lt;/P&gt;

&lt;P&gt;Please note the truncation of "total" and "pool" near the end of these examples down to "tota" and "po".  So this results in Splunk producing a few incorrect fields.  For example:&lt;/P&gt;

&lt;P&gt;msg.WO_data.feature.tota{@l}{@pool}&lt;BR /&gt;
which should be &lt;BR /&gt;
msg.WO_data.feature.total{@pool} &lt;/P&gt;

&lt;P&gt;and &lt;/P&gt;

&lt;P&gt;msg.WO_data.feature.total{@po}{@ol}&lt;BR /&gt;
which should be&lt;BR /&gt;
msg.WO_data.feature.total{@pool} &lt;/P&gt;

&lt;P&gt;I thought adding adding a SHOULD_LINEMERGE=true should work but I have not figured it out.  It either merges everything into one event, or when I prevent that it does not merge these lines to prevent the truncation.  &lt;/P&gt;

&lt;P&gt;I also tried adding a TRUNCATE option, but Splunk is not the one truncating so thats not the issue.  Any thoughts?  Thanks again for your effort and help.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:17:48 GMT</pubDate>
    <dc:creator>glihon</dc:creator>
    <dc:date>2020-09-28T13:17:48Z</dc:date>
    <item>
      <title>XML multi-value help</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-multi-value-help/m-p/27964#M1118</link>
      <description>&lt;P&gt;I am new to Splunk and have been reading as much as I can, but I cannot figure this out. Trying to wrap my head around regex.  I have some xml data as below.  Splunk only identifies the first values of bi, o, pb, pool, amt, mode.  I need to work with each of these.  Would you please help me make these multi-valued? Thank you.&lt;BR /&gt;
&amp;#3;&lt;/P&gt;

&lt;P&gt;Board 3  Msg #  90962   19-JAN-2013  12:45:34.51   msg length = 871&lt;BR /&gt;
&amp;#2;&lt;BR /&gt;
&lt;MSG&gt;&lt;BR /&gt;
&lt;HEADER recid="WO" meet="GULFSTREAM" race="07" perf="0036" nvid="019" ivr="19" tra1="GPM" tra2="GP  M" card="8" sesno="344" sesdate="2013-01-19" racedate="2013-01-19" ptyp="   $"&gt;&lt;/HEADER&gt;&lt;BR /&gt;
&lt;WO_DATA date="2013-01-19" time="12:45:34" post="12:38:00" trackc="SLOPPY" turfc="YIELDING" typ="F" total="0.00"&gt;&lt;BR /&gt;
&lt;ODDSDATA&gt;&lt;BR /&gt;
 &lt;ENTRY bi="1" o="5/2" pb="3.90"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="2" o=" 60" pb="64.40"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="3" o="  4" pb="5.30"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="4" o="6/5" pb="2.20"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="5" o="  4" pb="5.40"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="6" o=" 17" pb="18.10"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
 &lt;ENTRY bi="7" o=" 15" pb="16.10"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;
&lt;/ODDSDATA&gt;&lt;BR /&gt;
&lt;FEATURE&gt; &lt;BR /&gt;
 &lt;TOTAL pool="EX " amt="238035.59" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
 &lt;TOTAL pool="TRI" amt="135852.36" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
 &lt;TOTAL pool="DD " amt="40299.99" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
 &lt;TOTAL pool="P03" amt="45939.06" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
 &lt;TOTAL pool="P05" amt="181860.94" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
 &lt;TOTAL pool="SPR" amt="77642.62" mode="N"&gt;&lt;/TOTAL&gt;&lt;BR /&gt;
&lt;/FEATURE&gt; &lt;BR /&gt;
&lt;/WO_DATA&gt;&lt;BR /&gt;
&lt;/MSG&gt;&lt;/P&gt;

&lt;P&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;/P&gt;

&lt;P&gt;Sorry for the delayed response.  Thank you both for trying to help, it is greatly appreciated.  There are more issues with my data than I thought.  I was working with a friend who has more experience with Splunk and he helped me get a decent start.  Unfortunately, now I have issues with line breaking.  I am trying to index the above type messages from a txt file.  In the txt file it it looks like.&lt;/P&gt;

&lt;P&gt;Board 3 &lt;EM&gt;stuff&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;XML &lt;EM&gt;stuff&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Board 3 &lt;EM&gt;stuff&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;XML &lt;EM&gt;stuff&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Where each event is within one line separated by the "Board 3..." stuff.  He helped me over come this using the following props.conf:&lt;/P&gt;

&lt;P&gt;[horsexml]&lt;BR /&gt;
#TIME_PREFIX = Board\s\d+\s+\w+\s#\s+\d+\s+&lt;BR /&gt;
#TIME_FORMAT = %d-%b-%Y  %H:%M:%S.%2N&lt;BR /&gt;
LINE_BREAKER = (Board[\s\d\w#-:=\]+)|(\x3)&lt;BR /&gt;
SHOULD_LINEMERGE = false&lt;BR /&gt;
KV_MODE = xml&lt;BR /&gt;
#REPORT-xmlext = xml-extr&lt;/P&gt;

&lt;P&gt;Unfortunately, there exist "returns" within each line begun with &lt;MSG&gt; after 133 characters.  So instead of one straight line of xml code Splunk sees something like this&lt;/MSG&gt;&lt;/P&gt;

&lt;P&gt;&amp;#3;&lt;/P&gt;

&lt;P&gt;&amp;#3;&lt;/P&gt;

&lt;P&gt;Board 3  Msg #  24830   19-JAN-2013  08:47:01.13   msg length = 855&lt;BR /&gt;
&amp;#2;&lt;BR /&gt;
&lt;MSG&gt;&lt;HEADER recid="WO" meet="GULFSTREAM" race="01" perf="0036" nvid="019" ivr="19" tra1="GPM" tra2="GP  M" card="8" sesno="344"&gt;&lt;BR /&gt;
SesDate="2013-01-19" RaceDate="2013-01-19" PTyp="   $" /&amp;gt;&lt;WO_DATA date="2013-01-19" time="08:47:01" post="09:45:00" trackc="SLOPPY"&gt;&lt;BR /&gt;
turfC="YIELDING" typ="A" Total="0.00"&amp;gt;&lt;ODDSDATA&gt;&lt;ENTRY bi="1" o=" 40" pb="42.40"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="2" o=" 80" pb="82.30"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="3"&gt;&lt;BR /&gt;
o=" 30" pb="35.40" /&amp;gt;&lt;ENTRY bi="4" o=" 50" pb="56.70"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="5" o=" 99" pb="124.20"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="6" o="1/9" pb="1.10"&gt;&lt;/ENTRY&gt;&lt;ENTRY&gt;&lt;BR /&gt;
 bi="7" o="  5" pb="6.50" /&amp;gt;&lt;ENTRY bi="8" o=" 15" pb="16.80"&gt;&lt;/ENTRY&gt;&lt;/ENTRY&gt;&lt;FEATURE&gt; &lt;TOTAL pool="EX " amt="2055.74" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTA&gt;&lt;BR /&gt;
l pool="TRI" amt="937.58" mode="N" /&amp;gt;&lt;TOTAL pool="DD " amt="2624.10" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTAL pool="P03" amt="2033.60" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTAL po=""&gt;&lt;BR /&gt;
ol="SPR" amt="800.76" mode="N" /&amp;gt;&lt;/TOTAL&gt; &lt;/TOTA&gt;&lt;/FEATURE&gt;&lt;BR /&gt;
&amp;#3;&lt;/ENTRY&gt;&lt;/ODDSDATA&gt;&lt;/WO_DATA&gt;&lt;/HEADER&gt;&lt;/MSG&gt;&lt;/P&gt;

&lt;P&gt;Board 3  Msg #  24944   19-JAN-2013  08:47:36.09   msg length = 855&lt;BR /&gt;
&amp;#2;&lt;BR /&gt;
&lt;MSG&gt;&lt;HEADER recid="WO" meet="GULFSTREAM" race="01" perf="0036" nvid="019" ivr="19" tra1="GPM" tra2="GP  M" card="8" sesno="344"&gt;&lt;BR /&gt;
SesDate="2013-01-19" RaceDate="2013-01-19" PTyp="   $" /&amp;gt;&lt;WO_DATA date="2013-01-19" time="08:47:36" post="09:45:00" trackc="SLOPPY"&gt;&lt;BR /&gt;
turfC="YIELDING" typ="A" Total="0.00"&amp;gt;&lt;ODDSDATA&gt;&lt;ENTRY bi="1" o=" 40" pb="41.50"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="2" o=" 80" pb="81.60"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="3"&gt;&lt;BR /&gt;
o=" 30" pb="35.50" /&amp;gt;&lt;ENTRY bi="4" o=" 50" pb="57.00"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="5" o=" 99" pb="122.40"&gt;&lt;/ENTRY&gt;&lt;ENTRY bi="6" o="1/9" pb="1.10"&gt;&lt;/ENTRY&gt;&lt;ENTRY&gt;&lt;BR /&gt;
 bi="7" o="  5" pb="6.40" /&amp;gt;&lt;ENTRY bi="8" o=" 15" pb="16.90"&gt;&lt;/ENTRY&gt;&lt;/ENTRY&gt;&lt;FEATURE&gt; &lt;TOTAL pool="EX " amt="2077.34" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTA&gt;&lt;BR /&gt;
l pool="TRI" amt="949.05" mode="N" /&amp;gt;&lt;TOTAL pool="DD " amt="2708.90" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTAL pool="P03" amt="2033.50" mode="N"&gt;&lt;/TOTAL&gt;&lt;TOTAL po=""&gt;&lt;BR /&gt;
ol="SPR" amt="808.82" mode="N" /&amp;gt;&lt;/TOTAL&gt; &lt;/TOTA&gt;&lt;/FEATURE&gt;&lt;/ENTRY&gt;&lt;/ODDSDATA&gt;&lt;/WO_DATA&gt;&lt;/HEADER&gt;&lt;/MSG&gt;&lt;/P&gt;

&lt;P&gt;Please note the truncation of "total" and "pool" near the end of these examples down to "tota" and "po".  So this results in Splunk producing a few incorrect fields.  For example:&lt;/P&gt;

&lt;P&gt;msg.WO_data.feature.tota{@l}{@pool}&lt;BR /&gt;
which should be &lt;BR /&gt;
msg.WO_data.feature.total{@pool} &lt;/P&gt;

&lt;P&gt;and &lt;/P&gt;

&lt;P&gt;msg.WO_data.feature.total{@po}{@ol}&lt;BR /&gt;
which should be&lt;BR /&gt;
msg.WO_data.feature.total{@pool} &lt;/P&gt;

&lt;P&gt;I thought adding adding a SHOULD_LINEMERGE=true should work but I have not figured it out.  It either merges everything into one event, or when I prevent that it does not merge these lines to prevent the truncation.  &lt;/P&gt;

&lt;P&gt;I also tried adding a TRUNCATE option, but Splunk is not the one truncating so thats not the issue.  Any thoughts?  Thanks again for your effort and help.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:17:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/XML-multi-value-help/m-p/27964#M1118</guid>
      <dc:creator>glihon</dc:creator>
      <dc:date>2020-09-28T13:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: XML multi-value help</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-multi-value-help/m-p/27965#M1119</link>
      <description>&lt;P&gt;This'll give you multi-value fields:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...  | spath output=bi path=msg.wo_data.oddsdata.entry{@bi} | spath output=o path=msg.wo_data.oddsdata.entry{@o} | spath output=pb path=msg.wo_data.oddsdata.entry{@pb} | spath output=pool path=msg.wo_data.feature.total{@pool} | spath output=amt path=msg.wo_data.feature.total{@amt} | spath output=mode path=msg.wo_data.feature.total{@mode}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 11 Feb 2013 23:59:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/XML-multi-value-help/m-p/27965#M1119</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-02-11T23:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: XML multi-value help</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/XML-multi-value-help/m-p/27966#M1120</link>
      <description>&lt;P&gt;Try using &lt;CODE&gt;spath&lt;/CODE&gt; or setting the &lt;CODE&gt;KV_MODE=xml&lt;/CODE&gt; for your sourcetype which will parse your xml for you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2013 00:04:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/XML-multi-value-help/m-p/27966#M1120</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2013-02-12T00:04:08Z</dc:date>
    </item>
  </channel>
</rss>

