<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do you extract fields from an XML file? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-you-extract-fields-from-an-XML-file/m-p/396187#M25939</link>
    <description>&lt;P&gt;sample data&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;MAINNODE&amp;gt;
     &amp;lt;NODE1 ID="C1" DATE="2018-11-16 09:20:01"&amp;gt;
        &amp;lt;NODE2&amp;gt;
            &amp;lt;NODE3 CODE="A1" AMOUNT="100"/&amp;gt;
            &amp;lt;NODE3 CODE="A2" AMOUNT="200"/&amp;gt;
            &amp;lt;NODE3 CODE="A3" AMOUNT="300"/&amp;gt;
        &amp;lt;/NODE2&amp;gt;
    &amp;lt;/NODE1&amp;gt;
    &amp;lt;NODE1 ID="C2" DATE="2018-11-16 09:20:01"&amp;gt;
        &amp;lt;NODE2&amp;gt;
            &amp;lt;NODE3 CODE="A2" AMOUNT="100"/&amp;gt;
            &amp;lt;NODE3 CODE="A1" AMOUNT="200"/&amp;gt;
        &amp;lt;/NODE2&amp;gt;
    &amp;lt;/NODE1&amp;gt;
 &amp;lt;/MAINNODE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Can you please help me out to build a regular expression or any other method (ex: xpath) to get the rows as mentioned below.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ID="C1", DATE="2018-11-16 09:20:01", CODE="A1", AMOUNT="100"
ID="C1", DATE="2018-11-16 09:20:01", CODE="A2", AMOUNT="200"
ID="C1", DATE="2018-11-16 09:20:01", CODE="A3", AMOUNT="300"
ID="C2", DATE="2018-11-16 09:20:01", CODE="A2", AMOUNT="100"
ID="C2", DATE="2018-11-16 09:20:01", CODE="A1", AMOUNT="200"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 19 Nov 2018 11:53:32 GMT</pubDate>
    <dc:creator>varmamkm</dc:creator>
    <dc:date>2018-11-19T11:53:32Z</dc:date>
    <item>
      <title>How do you extract fields from an XML file?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-you-extract-fields-from-an-XML-file/m-p/396187#M25939</link>
      <description>&lt;P&gt;sample data&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;MAINNODE&amp;gt;
     &amp;lt;NODE1 ID="C1" DATE="2018-11-16 09:20:01"&amp;gt;
        &amp;lt;NODE2&amp;gt;
            &amp;lt;NODE3 CODE="A1" AMOUNT="100"/&amp;gt;
            &amp;lt;NODE3 CODE="A2" AMOUNT="200"/&amp;gt;
            &amp;lt;NODE3 CODE="A3" AMOUNT="300"/&amp;gt;
        &amp;lt;/NODE2&amp;gt;
    &amp;lt;/NODE1&amp;gt;
    &amp;lt;NODE1 ID="C2" DATE="2018-11-16 09:20:01"&amp;gt;
        &amp;lt;NODE2&amp;gt;
            &amp;lt;NODE3 CODE="A2" AMOUNT="100"/&amp;gt;
            &amp;lt;NODE3 CODE="A1" AMOUNT="200"/&amp;gt;
        &amp;lt;/NODE2&amp;gt;
    &amp;lt;/NODE1&amp;gt;
 &amp;lt;/MAINNODE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Can you please help me out to build a regular expression or any other method (ex: xpath) to get the rows as mentioned below.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ID="C1", DATE="2018-11-16 09:20:01", CODE="A1", AMOUNT="100"
ID="C1", DATE="2018-11-16 09:20:01", CODE="A2", AMOUNT="200"
ID="C1", DATE="2018-11-16 09:20:01", CODE="A3", AMOUNT="300"
ID="C2", DATE="2018-11-16 09:20:01", CODE="A2", AMOUNT="100"
ID="C2", DATE="2018-11-16 09:20:01", CODE="A1", AMOUNT="200"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 19 Nov 2018 11:53:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-you-extract-fields-from-an-XML-file/m-p/396187#M25939</guid>
      <dc:creator>varmamkm</dc:creator>
      <dc:date>2018-11-19T11:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: How do you extract fields from an XML file?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-you-extract-fields-from-an-XML-file/m-p/396188#M25940</link>
      <description>&lt;P&gt;Why does it have to be a regular expression?  Have you considered the &lt;CODE&gt;xpath&lt;/CODE&gt; command?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 13:44:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-you-extract-fields-from-an-XML-file/m-p/396188#M25940</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-11-19T13:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do you extract fields from an XML file?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-you-extract-fields-from-an-XML-file/m-p/396189#M25941</link>
      <description>&lt;P&gt;Thanks! i have solved this by using spath.. can you please validate the query below&lt;/P&gt;

&lt;P&gt;index="xmlfile" | spath output=NODE3CODE path=NODE1.NODE2.NODE3{@CODE} | spath output=NODE3AMOUNT path=NODE1.NODE2.NODE3{@AMOUNT} | eval x=mvzip(NODE3CODE, NODE3AMOUNT) | mvexpand x | eval x = split(x,",") | eval NODE3CODE=mvindex(x,0) | eval NODE3AMOUNT=mvindex(x,1) | table DATE ID NODE3CODE NODE3AMOUNT&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 15:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-you-extract-fields-from-an-XML-file/m-p/396189#M25941</guid>
      <dc:creator>varmamkm</dc:creator>
      <dc:date>2018-11-19T15:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do you extract fields from an XML file?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-you-extract-fields-from-an-XML-file/m-p/396190#M25942</link>
      <description>&lt;P&gt;You can obviously do all sort of things during index-time. However, if search time, this app probably has everything you need:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="https://splunkbase.splunk.com/app/455/" target="test_blank"&gt;https://splunkbase.splunk.com/app/455/&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;if you had this app, your search would look like&lt;BR /&gt;
index="xmlfile" | xmlkv&lt;/P&gt;

&lt;P&gt;if you need nested xml to be extracted,&lt;BR /&gt;
index="xmlfile" |xmlkvrecursive&lt;/P&gt;

&lt;P&gt;as mentioned, spath or rex would work on this task too. &lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2018 17:27:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-you-extract-fields-from-an-XML-file/m-p/396190#M25942</guid>
      <dc:creator>akocak</dc:creator>
      <dc:date>2018-11-19T17:27:39Z</dc:date>
    </item>
  </channel>
</rss>

