<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log ingested having xml tags that are not having fields extracted and named as per the tags? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480323#M31491</link>
    <description>&lt;P&gt;• Attached you will see a sample of the log I am working with.   &amp;lt;-- tried to attach it but not enough points.  Haha!&lt;/P&gt;

&lt;P&gt;• You will see in the body of the log row there are xml tags.  Like CorrelationId, MessageId, DateTime, Status, Action, Message.&lt;/P&gt;

&lt;P&gt;• I would think that Splunk would at least attempt to recognized these "xml tagged" field and name them.&lt;/P&gt;

&lt;P&gt;• Is it not recognizing the xml tags because the FULL log is not xml tagged &amp;amp; the beginning few positions aren't xml tagged?&lt;/P&gt;

&lt;P&gt;• Any thoughts or suggestions appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jan 2020 23:25:12 GMT</pubDate>
    <dc:creator>timothytruax</dc:creator>
    <dc:date>2020-01-07T23:25:12Z</dc:date>
    <item>
      <title>Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480323#M31491</link>
      <description>&lt;P&gt;• Attached you will see a sample of the log I am working with.   &amp;lt;-- tried to attach it but not enough points.  Haha!&lt;/P&gt;

&lt;P&gt;• You will see in the body of the log row there are xml tags.  Like CorrelationId, MessageId, DateTime, Status, Action, Message.&lt;/P&gt;

&lt;P&gt;• I would think that Splunk would at least attempt to recognized these "xml tagged" field and name them.&lt;/P&gt;

&lt;P&gt;• Is it not recognizing the xml tags because the FULL log is not xml tagged &amp;amp; the beginning few positions aren't xml tagged?&lt;/P&gt;

&lt;P&gt;• Any thoughts or suggestions appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 23:25:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480323#M31491</guid>
      <dc:creator>timothytruax</dc:creator>
      <dc:date>2020-01-07T23:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480324#M31492</link>
      <description>&lt;P&gt;Please copy-and-paste some sample data.&lt;BR /&gt;
Please also share the props.conf file settings for the sourcetype.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 00:56:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480324#M31492</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-01-08T00:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480325#M31493</link>
      <description>&lt;P&gt;Hi Rich - I will send it first thing tomorrow morning.   Thank you for your attention to my question.   Tim&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 01:06:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480325#M31493</guid>
      <dc:creator>timothytruax</dc:creator>
      <dc:date>2020-01-08T01:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480326#M31494</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Log row....&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;000 2 00 0000 2020-01-08 13:52:48.771 (PickupStatusListener:41) Message payload:  4dba36a5-076b-4dc6-bde5-04366a4dcb78bf6cd527-fb0b-4f08-8920-f1c01d498764c4b3cc79-c4bb-4512-a3b7-f1527cf034911570a3c5-fab3-4ad3-ad13-5ed8831717122020-01-08T13:52:48.717-05:002020-01-08T13:52:27-05:00ReadReceiptRequest to remove pickup from manifest was received by the scanner.BRK_APPTransferRequestRemove314&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Props.conf for sourcetype...&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;-bash-4.2$ cat props.conf&lt;BR /&gt;
[kedex:cpc:log]&lt;BR /&gt;
SHOULD_LINEMERGE=false&lt;BR /&gt;
LINE_BREAKER=([\r\n]+)\d{3}\s+\d{1}\s+\d{2}\s+\d{4}&lt;BR /&gt;
NO_BINARY_CHECK=true&lt;BR /&gt;
disabled=false&lt;BR /&gt;
TIME_PREFIX=\s+\d{4}\s+&lt;BR /&gt;
TIME_FORMAT=%F %T.%3N&lt;BR /&gt;
TRUNCATE=999999&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD=35&lt;/P&gt;

&lt;P&gt;[kedex:cpc:gc]&lt;BR /&gt;
SHOULD_LINEMERGE=false&lt;BR /&gt;
TIME_PREFIX=^&lt;BR /&gt;
LINE_BREAKER=([\r\n]+)\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}&lt;BR /&gt;
TIME_FORMAT=%FT%T.%3N&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD=25&lt;BR /&gt;
TRUNCATE=999999&lt;/P&gt;

&lt;P&gt;[kedex:cpc:error]&lt;BR /&gt;
SHOULD_LINEMERGE=false&lt;BR /&gt;
TIME_PREFIX=^\d+\s+\d+\s+\d+\s+\d+\s+&lt;BR /&gt;
LINE_BREAKER=([\r\n]+)\d+\s+\d+\s+\d+\s+\d+\s+\d{4}-\d{2}-\d{2}&lt;BR /&gt;
TIME_FORMAT=%F %T.%3N&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD=25&lt;BR /&gt;
TRUNCATE=999999&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:36:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480326#M31494</guid>
      <dc:creator>timothytruax</dc:creator>
      <dc:date>2020-09-30T03:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480327#M31495</link>
      <description>&lt;P&gt;There are no XML tags in the sample log row.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 03:27:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480327#M31495</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-01-13T03:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480328#M31496</link>
      <description>&lt;P&gt;I am unable to upload an image of this log row - AND - when I copy and paste the text of the log row it strips out my xml tags.  How else can I get the text or an image of this log row to you.&lt;BR /&gt;&lt;BR /&gt;
For some reason they say I do not have enough "points" to upload a small image of the log row.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 13:27:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480328#M31496</guid>
      <dc:creator>timothytruax</dc:creator>
      <dc:date>2020-01-14T13:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480329#M31497</link>
      <description>&lt;P&gt;For some reason when I copy / paste the log row this field strips out my xml tags.&lt;BR /&gt;
Also when I try to upload a small image of the log row this site tells me I do not have enough points to upload the file.&lt;BR /&gt;
Therefore this site and any interaction thru the SPLUNK provided field for pasting data is virtually worthless!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 13:29:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480329#M31497</guid>
      <dc:creator>timothytruax</dc:creator>
      <dc:date>2020-01-14T13:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480330#M31498</link>
      <description>&lt;P&gt;Is there ANY OTHER way I can get this image of the log row to you?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 13:30:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480330#M31498</guid>
      <dc:creator>timothytruax</dc:creator>
      <dc:date>2020-01-14T13:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480331#M31499</link>
      <description>&lt;P&gt;For some reason when I copy / paste the log row this field strips out my xml tags.&lt;BR /&gt;
Also when I try to upload a small image of the log row this site tells me I do not have enough points to upload the file.&lt;BR /&gt;
Therefore this site and any interaction thru the SPLUNK provided field for pasting data is virtually worthless!   Is there any other way I can get this log row to you?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 13:31:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480331#M31499</guid>
      <dc:creator>timothytruax</dc:creator>
      <dc:date>2020-01-14T13:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480332#M31500</link>
      <description>&lt;P&gt;To avoid losing XML tags and other formatting characters, enclose the text within backtics (`) or highlight it and click the code button (101010).&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 13:39:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480332#M31500</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-01-14T13:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480333#M31501</link>
      <description>&lt;P&gt;Thanks Rich!  I will remember that!!   Here is the log row....&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;000 2 00 0000 2020-01-08 13:52:48.771 (PickupStatusListener:41) Message payload: &amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt; &amp;lt;ns0:PickupStatus xmlns:ns0="http://cpc.ground.fedex.com/pickup/status/v1"&amp;gt;&amp;lt;CorrelationId&amp;gt;4dba36a5-076b-4dc6-bde5-04366a4dcb78&amp;lt;/CorrelationId&amp;gt;&amp;lt;MessageId&amp;gt;bf6cd527-fb0b-4f08-8920-f1c01d498764&amp;lt;/MessageId&amp;gt;&amp;lt;ParentMessageId&amp;gt;c4b3cc79-c4bb-4512-a3b7-f1527cf03491&amp;lt;/ParentMessageId&amp;gt;&amp;lt;StatusForMessageId&amp;gt;1570a3c5-fab3-4ad3-ad13-5ed883171712&amp;lt;/StatusForMessageId&amp;gt;&amp;lt;DateTime&amp;gt;2020-01-08T13:52:48.717-05:00&amp;lt;/DateTime&amp;gt;&amp;lt;SourceSentDateTime&amp;gt;2020-01-08T13:52:27-05:00&amp;lt;/SourceSentDateTime&amp;gt;&amp;lt;Status&amp;gt;ReadReceipt&amp;lt;/Status&amp;gt;&amp;lt;Message&amp;gt;Request to remove pickup from manifest was received by the scanner.&amp;lt;/Message&amp;gt;&amp;lt;UserId&amp;gt;BRK_APP&amp;lt;/UserId&amp;gt;&amp;lt;RequestType&amp;gt;TransferRequest&amp;lt;/RequestType&amp;gt;&amp;lt;Action&amp;gt;Remove&amp;lt;/Action&amp;gt;&amp;lt;TerminalNumber&amp;gt;314&amp;lt;/TerminalNumber&amp;gt;&amp;lt;/ns0:PickupStatus&amp;gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 11:38:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480333#M31501</guid>
      <dc:creator>timothytruax</dc:creator>
      <dc:date>2020-01-15T11:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480334#M31502</link>
      <description>&lt;PRE&gt;&lt;CODE&gt; `   000 2 00 0000 2020-01-08 13:52:48.771 (PickupStatusListener:41) Message payload: &amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt; &amp;lt;ns0:PickupStatus xmlns:ns0="http://cpc.ground.fedex.com/pickup/status/v1"&amp;gt;&amp;lt;CorrelationId&amp;gt;4dba36a5-076b-4dc6-bde5-04366a4dcb78&amp;lt;/CorrelationId&amp;gt;&amp;lt;MessageId&amp;gt;bf6cd527-fb0b-4f08-8920-f1c01d498764&amp;lt;/MessageId&amp;gt;&amp;lt;ParentMessageId&amp;gt;c4b3cc79-c4bb-4512-a3b7-f1527cf03491&amp;lt;/ParentMessageId&amp;gt;&amp;lt;StatusForMessageId&amp;gt;1570a3c5-fab3-4ad3-ad13-5ed883171712&amp;lt;/StatusForMessageId&amp;gt;&amp;lt;DateTime&amp;gt;2020-01-08T13:52:48.717-05:00&amp;lt;/DateTime&amp;gt;&amp;lt;SourceSentDateTime&amp;gt;2020-01-08T13:52:27-05:00&amp;lt;/SourceSentDateTime&amp;gt;&amp;lt;Status&amp;gt;ReadReceipt&amp;lt;/Status&amp;gt;&amp;lt;Message&amp;gt;Request to remove pickup from manifest was received by the scanner.&amp;lt;/Message&amp;gt;&amp;lt;UserId&amp;gt;BRK_APP&amp;lt;/UserId&amp;gt;&amp;lt;RequestType&amp;gt;TransferRequest&amp;lt;/RequestType&amp;gt;&amp;lt;Action&amp;gt;Remove&amp;lt;/Action&amp;gt;&amp;lt;TerminalNumber&amp;gt;314&amp;lt;/TerminalNumber&amp;gt;&amp;lt;/ns0:PickupStatus&amp;gt; `
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 15 Jan 2020 11:40:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480334#M31502</guid>
      <dc:creator>timothytruax</dc:creator>
      <dc:date>2020-01-15T11:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480335#M31503</link>
      <description>&lt;P&gt;What appears to be happening is the timestamp fields can vary in length and appearance; so when we attempt to use the extractor to create as field that is past one of those varying timestamps we get unmatched rows in the extractor.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 11:44:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480335#M31503</guid>
      <dc:creator>timothytruax</dc:creator>
      <dc:date>2020-01-15T11:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Log ingested having xml tags that are not having fields extracted and named as per the tags?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480336#M31504</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval _raw="000 2 00 0000 2020-01-08 13:52:48.771 (PickupStatusListener:41) Message payload: &amp;lt;?xml version=\"1.0\" encoding=\"UTF-8\"?&amp;gt; &amp;lt;ns0:PickupStatus xmlns:ns0=\"http://cpc.ground.fedex.com/pickup/status/v1\"&amp;gt;&amp;lt;CorrelationId&amp;gt;4dba36a5-076b-4dc6-bde5-04366a4dcb78&amp;lt;/CorrelationId&amp;gt;&amp;lt;MessageId&amp;gt;bf6cd527-fb0b-4f08-8920-f1c01d498764&amp;lt;/MessageId&amp;gt;&amp;lt;ParentMessageId&amp;gt;c4b3cc79-c4bb-4512-a3b7-f1527cf03491&amp;lt;/ParentMessageId&amp;gt;&amp;lt;StatusForMessageId&amp;gt;1570a3c5-fab3-4ad3-ad13-5ed883171712&amp;lt;/StatusForMessageId&amp;gt;&amp;lt;DateTime&amp;gt;2020-01-08T13:52:48.717-05:00&amp;lt;/DateTime&amp;gt;&amp;lt;SourceSentDateTime&amp;gt;2020-01-08T13:52:27-05:00&amp;lt;/SourceSentDateTime&amp;gt;&amp;lt;Status&amp;gt;ReadReceipt&amp;lt;/Status&amp;gt;&amp;lt;Message&amp;gt;Request to remove pickup from manifest was received by the scanner.&amp;lt;/Message&amp;gt;&amp;lt;UserId&amp;gt;BRK_APP&amp;lt;/UserId&amp;gt;&amp;lt;RequestType&amp;gt;TransferRequest&amp;lt;/RequestType&amp;gt;&amp;lt;Action&amp;gt;Remove&amp;lt;/Action&amp;gt;&amp;lt;TerminalNumber&amp;gt;314&amp;lt;/TerminalNumber&amp;gt;&amp;lt;/ns0:PickupStatus&amp;gt;" 
| rex "(?&amp;lt;xml_data&amp;gt;(?=\&amp;lt;).+)"
| rex "(?&amp;lt;time&amp;gt;\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}\.\d{3})" 
| spath input=xml_data
| fields - _* xml_data
| eval _time=strptime(time,"%F %T.%3Q")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hi, @timothytruax &lt;BR /&gt;
If there is data in &lt;CODE&gt;_raw&lt;/CODE&gt; , it can be extracted like this.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 12:33:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Log-ingested-having-xml-tags-that-are-not-having-fields/m-p/480336#M31504</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-01-15T12:33:37Z</dc:date>
    </item>
  </channel>
</rss>

