<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XML Field Extraction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359254#M106219</link>
    <description>&lt;P&gt;@mintucs, you might have to post a separate question with your sample xml data and extraction that you are using. If applicable your props.conf and transforms.conf as well. You would also need to mask any sensitive information while posting your question.&lt;/P&gt;</description>
    <pubDate>Mon, 28 May 2018 08:22:25 GMT</pubDate>
    <dc:creator>niketn</dc:creator>
    <dc:date>2018-05-28T08:22:25Z</dc:date>
    <item>
      <title>XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359241#M106206</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Here's a sample of my XML data.  I want to get the username.  I tried a field alias, but that's not working, nor is field extraction.  When I open the field extractor tool, the data is truncated after the caller_profile tag.  When I look at the event, it's all there.  It's only when I try to use the field extractor that it gets truncated.&lt;/P&gt;

&lt;P&gt;props.conf:&lt;BR /&gt;
[conf_cdr_xml]&lt;BR /&gt;
TRUNCATE = 0&lt;BR /&gt;
KV_MODE = xml&lt;/P&gt;

&lt;P&gt;date sample:&lt;BR /&gt;
    &lt;CDR&gt;&lt;BR /&gt;
      &lt;CONFERENCE&gt;&lt;BR /&gt;
        &lt;NAME&gt;1235551234-101&lt;/NAME&gt;&lt;BR /&gt;
        &lt;HOSTNAME&gt;hostname.com&lt;/HOSTNAME&gt;&lt;BR /&gt;
        &lt;RATE&gt;8000&lt;/RATE&gt;&lt;BR /&gt;
        &lt;INTERVAL&gt;20&lt;/INTERVAL&gt;&lt;BR /&gt;
        &lt;START_TIME type="UNIX-epoch"&gt;1510329526&lt;/START_TIME&gt;&lt;BR /&gt;
        &lt;END_TIME endconference_forced="false" type="UNIX-epoch"&gt;1510329534&lt;/END_TIME&gt;&lt;BR /&gt;
        &lt;MEMBERS&gt;&lt;BR /&gt;
          &lt;MEMBER type="caller"&gt;&lt;BR /&gt;
            &lt;JOIN_TIME type="UNIX-epoch"&gt;1510329526&lt;/JOIN_TIME&gt;&lt;BR /&gt;
            &lt;LEAVE_TIME type="UNIX-epoch"&gt;1510329534&lt;/LEAVE_TIME&gt;&lt;BR /&gt;
            &lt;FLAGS&gt;&lt;BR /&gt;
              &lt;IS_MODERATOR&gt;true&lt;/IS_MODERATOR&gt;&lt;BR /&gt;
              &lt;END_CONFERENCE&gt;true&lt;/END_CONFERENCE&gt;&lt;BR /&gt;
              &lt;WAS_KICKED&gt;false&lt;/WAS_KICKED&gt;&lt;BR /&gt;
              &lt;IS_GHOST&gt;false&lt;/IS_GHOST&gt;&lt;BR /&gt;
            &lt;/FLAGS&gt;&lt;BR /&gt;
            &lt;CALLER_PROFILE&gt;&lt;BR /&gt;
              &lt;USERNAME&gt;1235551010&lt;/USERNAME&gt;&lt;BR /&gt;
              &lt;DIALPLAN&gt;XML&lt;/DIALPLAN&gt;&lt;BR /&gt;
              &lt;CALLER_ID_NAME&gt;Joe Boss&lt;/CALLER_ID_NAME&gt;&lt;BR /&gt;
              &lt;CALLER_ID_NUMBER&gt;1235551010&lt;/CALLER_ID_NUMBER&gt;&lt;BR /&gt;
              &lt;CALLEE_ID_NAME&gt;&lt;/CALLEE_ID_NAME&gt;&lt;BR /&gt;
              &lt;CALLEE_ID_NUMBER&gt;&lt;/CALLEE_ID_NUMBER&gt;&lt;BR /&gt;
              &lt;ANI&gt;1235551010&lt;/ANI&gt;&lt;BR /&gt;
              &lt;ANIII&gt;&lt;/ANIII&gt;&lt;BR /&gt;
              &lt;NETWORK_ADDR&gt;10.0.1.1&lt;/NETWORK_ADDR&gt;&lt;BR /&gt;
              &lt;RDNIS&gt;&lt;/RDNIS&gt;&lt;BR /&gt;
              &lt;DESTINATION_NUMBER&gt;1235551234;conf=101;mod;tone=NO_SOUNDS&lt;/DESTINATION_NUMBER&gt;&lt;BR /&gt;
              &lt;UUID&gt;038fa0ce-c630-11e7-938f-b3cdceb36fa4&lt;/UUID&gt;&lt;BR /&gt;
              &lt;SOURCE&gt;mod_sofia&lt;/SOURCE&gt;&lt;BR /&gt;
              &lt;CONTEXT&gt;public&lt;/CONTEXT&gt;&lt;BR /&gt;
              &lt;CHAN_NAME&gt;sofia/internal/&lt;A href="mailto:1235551010@10.10.1.1" target="_blank"&gt;1235551010@10.10.1.1&lt;/A&gt;&lt;/CHAN_NAME&gt;&lt;BR /&gt;
            &lt;/CALLER_PROFILE&gt;&lt;BR /&gt;
          &lt;/MEMBER&gt;&lt;BR /&gt;
        &lt;/MEMBERS&gt;&lt;BR /&gt;
        &lt;REJECTED&gt;&lt;/REJECTED&gt;&lt;BR /&gt;
      &lt;/CONFERENCE&gt;&lt;BR /&gt;
    &lt;/CDR&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:41:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359241#M106206</guid>
      <dc:creator>mwcooley</dc:creator>
      <dc:date>2020-09-29T16:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359242#M106207</link>
      <description>&lt;P&gt;dang it.  the preview showed my xml as text.  one more try:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;cdr&amp;gt;
  &amp;lt;conference&amp;gt;
    &amp;lt;name&amp;gt;1235551234-101&amp;lt;/name&amp;gt;
    &amp;lt;hostname&amp;gt;hostname.com&amp;lt;/hostname&amp;gt;
    &amp;lt;rate&amp;gt;8000&amp;lt;/rate&amp;gt;
    &amp;lt;interval&amp;gt;20&amp;lt;/interval&amp;gt;
    &amp;lt;start_time type="UNIX-epoch"&amp;gt;1510329526&amp;lt;/start_time&amp;gt;
    &amp;lt;end_time endconference_forced="false" type="UNIX-epoch"&amp;gt;1510329534&amp;lt;/end_time&amp;gt;
    &amp;lt;members&amp;gt;
      &amp;lt;member type="caller"&amp;gt;
        &amp;lt;join_time type="UNIX-epoch"&amp;gt;1510329526&amp;lt;/join_time&amp;gt;
        &amp;lt;leave_time type="UNIX-epoch"&amp;gt;1510329534&amp;lt;/leave_time&amp;gt;
        &amp;lt;flags&amp;gt;
          &amp;lt;is_moderator&amp;gt;true&amp;lt;/is_moderator&amp;gt;
          &amp;lt;end_conference&amp;gt;true&amp;lt;/end_conference&amp;gt;
          &amp;lt;was_kicked&amp;gt;false&amp;lt;/was_kicked&amp;gt;
          &amp;lt;is_ghost&amp;gt;false&amp;lt;/is_ghost&amp;gt;
        &amp;lt;/flags&amp;gt;
        &amp;lt;caller_profile&amp;gt;
          &amp;lt;username&amp;gt;1235551010&amp;lt;/username&amp;gt;
          &amp;lt;dialplan&amp;gt;XML&amp;lt;/dialplan&amp;gt;
          &amp;lt;caller_id_name&amp;gt;Joe Boss&amp;lt;/caller_id_name&amp;gt;
          &amp;lt;caller_id_number&amp;gt;1235551010&amp;lt;/caller_id_number&amp;gt;
          &amp;lt;callee_id_name&amp;gt;&amp;lt;/callee_id_name&amp;gt;
          &amp;lt;callee_id_number&amp;gt;&amp;lt;/callee_id_number&amp;gt;
          &amp;lt;ani&amp;gt;1235551010&amp;lt;/ani&amp;gt;
          &amp;lt;aniii&amp;gt;&amp;lt;/aniii&amp;gt;
          &amp;lt;network_addr&amp;gt;10.0.1.1&amp;lt;/network_addr&amp;gt;
          &amp;lt;rdnis&amp;gt;&amp;lt;/rdnis&amp;gt;
          &amp;lt;destination_number&amp;gt;1235551234;conf=101;mod;tone=NO_SOUNDS&amp;lt;/destination_number&amp;gt;
          &amp;lt;uuid&amp;gt;038fa0ce-c630-11e7-938f-b3cdceb36fa4&amp;lt;/uuid&amp;gt;
          &amp;lt;source&amp;gt;mod_sofia&amp;lt;/source&amp;gt;
          &amp;lt;context&amp;gt;public&amp;lt;/context&amp;gt;
          &amp;lt;chan_name&amp;gt;sofia/internal/1235551010@10.10.1.1&amp;lt;/chan_name&amp;gt;
        &amp;lt;/caller_profile&amp;gt;
      &amp;lt;/member&amp;gt;
    &amp;lt;/members&amp;gt;
    &amp;lt;rejected&amp;gt;&amp;lt;/rejected&amp;gt;
  &amp;lt;/conference&amp;gt;
&amp;lt;/cdr&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 10 Nov 2017 16:15:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359242#M106207</guid>
      <dc:creator>mwcooley</dc:creator>
      <dc:date>2017-11-10T16:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359243#M106208</link>
      <description>&lt;P&gt;Try this in the props.conf&lt;/P&gt;

&lt;P&gt;[conf_cdr_xml]&lt;BR /&gt;
KV_MODE = xml&lt;BR /&gt;
SHOULD_LINEMERGE = true&lt;BR /&gt;
BREAK_ONLY_BEFORE = ((--NEVER--))&lt;BR /&gt;
MAX_EVENTS = 1000 &lt;BR /&gt;
NO_BINARY_CHECK = true&lt;BR /&gt;
pulldown_type = true&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:45:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359243#M106208</guid>
      <dc:creator>FrankSPL</dc:creator>
      <dc:date>2020-09-29T16:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359244#M106209</link>
      <description>&lt;P&gt;Hey.  Didn't work.  I forward to heavy forwarders which forward to indexes.  I'm worried something in the heavy forwarder is messing me up.  KV_MODE isn't working either.  But then, i'm a complete noob.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 19:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359244#M106209</guid>
      <dc:creator>mwcooley</dc:creator>
      <dc:date>2017-11-10T19:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359245#M106210</link>
      <description>&lt;P&gt;@mwcooley, so by &lt;CODE&gt;KV_MODE=xml&lt;/CODE&gt; not working do you mean Search Time Field discovery in smart/verbose mode is not working? The following table command does not work&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;YourBaseSearch&amp;gt;
|  table *username
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Have you also tried&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;YourBaseSearch&amp;gt;
| spath
|  table *username
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In case XML parsing is not working and you are able to see data with &lt;CODE&gt;&amp;lt;username&amp;gt;1235551010&amp;lt;/username&amp;gt;&lt;/CODE&gt;, then try the following &lt;CODE&gt;rex&lt;/CODE&gt; command and see how it behaves:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;YourBaseSearch&amp;gt;
|  rex "&amp;lt;username&amp;gt;(?&amp;lt;username&amp;gt;[^\&amp;lt;]+)&amp;lt;/username&amp;gt;"
|  table username
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 10 Nov 2017 21:15:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359245#M106210</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-11-10T21:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359246#M106211</link>
      <description>&lt;P&gt;@niketnilay, that's closer.   | spath | table *username works.  I get the usernames even when there are multiples.  The rex command only returns the first  .&lt;/P&gt;

&lt;P&gt;If I use spath, how do I get the username into eventstats?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 21:39:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359246#M106211</guid>
      <dc:creator>mwcooley</dc:creator>
      <dc:date>2017-11-10T21:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359247#M106212</link>
      <description>&lt;P&gt;so your events are already broken correctly and you're just working on field extractions?  If so, then the kv_mode setting should be on your search head.  Is it there?&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2017 13:46:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359247#M106212</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2017-11-11T13:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359248#M106213</link>
      <description>&lt;P&gt;@mwcooley, your sample data had only one username in the event. By the rex command only returning first match, do you mean that single event may have multiple usernames? Can you add such sample? &lt;/P&gt;

&lt;P&gt;In any case, you can use &lt;CODE&gt;max_match=0&lt;/CODE&gt; in the rex command to return multiple matches within single event. username field will be treated as multivalued.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;YourBaseSearch&amp;gt;
|  rex "&amp;lt;username&amp;gt;(?&amp;lt;username&amp;gt;[^&amp;lt;]+)&amp;lt;\/username&amp;gt;" max_match=0
|  table username
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What do you mean by eventstats? What is your intended output and which fields do you want to use and what is the desired output? In other words give the desired field names and expected values in tabular format.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2017 18:07:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359248#M106213</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-11-11T18:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359249#M106214</link>
      <description>&lt;P&gt;ah, OK.  I don't have access to the search head, only the forwarder.  i thought I could put it in props.conf there and make it work.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 15:24:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359249#M106214</guid>
      <dc:creator>mwcooley</dc:creator>
      <dc:date>2017-11-13T15:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359250#M106215</link>
      <description>&lt;P&gt;thanks &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/201110"&gt;@niketn&lt;/a&gt;, using max_match=0 worked.  here's the final search (turned out i needed callerID, not username):&lt;/P&gt;

&lt;P&gt;index="myIndex" sourcetype="conf_cdr_xml" | &lt;BR /&gt;
eval Conf_Start=strftime(start_time,"%H:%M:%S %m/%d/%y") |&lt;BR /&gt;&lt;BR /&gt;
eval Conf_End=strftime(end_time,"%H:%M:%S %m/%d/%y") |&lt;BR /&gt;&lt;BR /&gt;
eval Duration = tostring((end_time - start_time), "Duration") | &lt;BR /&gt;
rex "(?[^&amp;lt;]+)&amp;lt;\/caller_id_name&amp;gt;" max_match=0 |&lt;BR /&gt;
eventstats count(caller_id_name) as Attendees by Conf_Start | &lt;BR /&gt;
table confName Conf_Start Conf_End Duration Attendees&lt;/P&gt;

&lt;P&gt;An, here's the xml with multiple usernames/callerIDs:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;?xml version="1.0"?&amp;gt;
&amp;lt;cdr&amp;gt;
  &amp;lt;conference&amp;gt;
    &amp;lt;name&amp;gt;1235551234-101&amp;lt;/name&amp;gt;
    &amp;lt;hostname&amp;gt;hostname.com&amp;lt;/hostname&amp;gt;
    &amp;lt;rate&amp;gt;8000&amp;lt;/rate&amp;gt;
    &amp;lt;interval&amp;gt;20&amp;lt;/interval&amp;gt;
    &amp;lt;start_time type="UNIX-epoch"&amp;gt;1510329526&amp;lt;/start_time&amp;gt;
    &amp;lt;end_time endconference_forced="false" type="UNIX-epoch"&amp;gt;1510329534&amp;lt;/end_time&amp;gt;
    &amp;lt;members&amp;gt;
      &amp;lt;member type="caller"&amp;gt;
        &amp;lt;join_time type="UNIX-epoch"&amp;gt;1510329526&amp;lt;/join_time&amp;gt;
        &amp;lt;leave_time type="UNIX-epoch"&amp;gt;1510329534&amp;lt;/leave_time&amp;gt;
        &amp;lt;flags&amp;gt;
          &amp;lt;is_moderator&amp;gt;true&amp;lt;/is_moderator&amp;gt;
          &amp;lt;end_conference&amp;gt;true&amp;lt;/end_conference&amp;gt;
          &amp;lt;was_kicked&amp;gt;false&amp;lt;/was_kicked&amp;gt;
          &amp;lt;is_ghost&amp;gt;false&amp;lt;/is_ghost&amp;gt;
        &amp;lt;/flags&amp;gt;
        &amp;lt;caller_profile&amp;gt;
          &amp;lt;username&amp;gt;1235551010&amp;lt;/username&amp;gt;
          &amp;lt;dialplan&amp;gt;XML&amp;lt;/dialplan&amp;gt;
          &amp;lt;caller_id_name&amp;gt;Joe Boss&amp;lt;/caller_id_name&amp;gt;
          &amp;lt;caller_id_number&amp;gt;1235551010&amp;lt;/caller_id_number&amp;gt;
          &amp;lt;callee_id_name&amp;gt;&amp;lt;/callee_id_name&amp;gt;
          &amp;lt;callee_id_number&amp;gt;&amp;lt;/callee_id_number&amp;gt;
          &amp;lt;ani&amp;gt;1235551010&amp;lt;/ani&amp;gt;
          &amp;lt;aniii&amp;gt;&amp;lt;/aniii&amp;gt;
          &amp;lt;network_addr&amp;gt;10.0.1.1&amp;lt;/network_addr&amp;gt;
          &amp;lt;rdnis&amp;gt;&amp;lt;/rdnis&amp;gt;
          &amp;lt;destination_number&amp;gt;1235551234;conf=101;mod;tone=NO_SOUNDS&amp;lt;/destination_number&amp;gt;
          &amp;lt;uuid&amp;gt;038fa0ce-c630-11e7-938f-b3cdceb36fa4&amp;lt;/uuid&amp;gt;
          &amp;lt;source&amp;gt;mod_sofia&amp;lt;/source&amp;gt;
          &amp;lt;context&amp;gt;public&amp;lt;/context&amp;gt;
          &amp;lt;chan_name&amp;gt;sofia/internal/1235551010@10.10.1.1&amp;lt;/chan_name&amp;gt;
        &amp;lt;/caller_profile&amp;gt;
      &amp;lt;/member&amp;gt;
      &amp;lt;member type="caller"&amp;gt;
        &amp;lt;join_time type="UNIX-epoch"&amp;gt;1510329526&amp;lt;/join_time&amp;gt;
        &amp;lt;leave_time type="UNIX-epoch"&amp;gt;1510329534&amp;lt;/leave_time&amp;gt;
        &amp;lt;flags&amp;gt;
          &amp;lt;is_moderator&amp;gt;true&amp;lt;/is_moderator&amp;gt;
          &amp;lt;end_conference&amp;gt;true&amp;lt;/end_conference&amp;gt;
          &amp;lt;was_kicked&amp;gt;false&amp;lt;/was_kicked&amp;gt;
          &amp;lt;is_ghost&amp;gt;false&amp;lt;/is_ghost&amp;gt;
        &amp;lt;/flags&amp;gt;
        &amp;lt;caller_profile&amp;gt;
          &amp;lt;username&amp;gt;1235557721&amp;lt;/username&amp;gt;
          &amp;lt;dialplan&amp;gt;XML&amp;lt;/dialplan&amp;gt;
          &amp;lt;caller_id_name&amp;gt;Bob&amp;lt;/caller_id_name&amp;gt;
          &amp;lt;caller_id_number&amp;gt;1235557721&amp;lt;/caller_id_number&amp;gt;
          &amp;lt;callee_id_name&amp;gt;&amp;lt;/callee_id_name&amp;gt;
          &amp;lt;callee_id_number&amp;gt;&amp;lt;/callee_id_number&amp;gt;
          &amp;lt;ani&amp;gt;1235557721&amp;lt;/ani&amp;gt;
          &amp;lt;aniii&amp;gt;&amp;lt;/aniii&amp;gt;
          &amp;lt;network_addr&amp;gt;10.0.1.2&amp;lt;/network_addr&amp;gt;
          &amp;lt;rdnis&amp;gt;&amp;lt;/rdnis&amp;gt;
          &amp;lt;destination_number&amp;gt;1235551234;conf=101;mod;tone=NO_SOUNDS&amp;lt;/destination_number&amp;gt;
          &amp;lt;uuid&amp;gt;038fa0ce-c630-11e7-938f-b3cdceb36fa4&amp;lt;/uuid&amp;gt;
          &amp;lt;source&amp;gt;mod_sofia&amp;lt;/source&amp;gt;
          &amp;lt;context&amp;gt;public&amp;lt;/context&amp;gt;
          &amp;lt;chan_name&amp;gt;sofia/internal/1235557721@10.10.1.2&amp;lt;/chan_name&amp;gt;
        &amp;lt;/caller_profile&amp;gt;
      &amp;lt;/member&amp;gt;
      &amp;lt;/members&amp;gt;
    &amp;lt;rejected&amp;gt;&amp;lt;/rejected&amp;gt;
  &amp;lt;/conference&amp;gt;
&amp;lt;/cdr&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:43:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359250#M106215</guid>
      <dc:creator>mwcooley</dc:creator>
      <dc:date>2020-09-29T16:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359251#M106216</link>
      <description>&lt;P&gt;I want to count the users, so i was trying to feed the usernames to eventstats.  the final search is in a comment below.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 15:27:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359251#M106216</guid>
      <dc:creator>mwcooley</dc:creator>
      <dc:date>2017-11-13T15:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359252#M106217</link>
      <description>&lt;P&gt;Glad it worked. Do compare &lt;CODE&gt;stats&lt;/CODE&gt; and &lt;CODE&gt;eventstats&lt;/CODE&gt; and see which one you actually need.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 15:32:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359252#M106217</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-11-13T15:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359253#M106218</link>
      <description>&lt;P&gt;in case xml using above solution &lt;/P&gt;

&lt;P&gt;getting only single result&lt;/P&gt;</description>
      <pubDate>Mon, 28 May 2018 06:35:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359253#M106218</guid>
      <dc:creator>mintucs</dc:creator>
      <dc:date>2018-05-28T06:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: XML Field Extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359254#M106219</link>
      <description>&lt;P&gt;@mintucs, you might have to post a separate question with your sample xml data and extraction that you are using. If applicable your props.conf and transforms.conf as well. You would also need to mask any sensitive information while posting your question.&lt;/P&gt;</description>
      <pubDate>Mon, 28 May 2018 08:22:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-Field-Extraction/m-p/359254#M106219</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-05-28T08:22:25Z</dc:date>
    </item>
  </channel>
</rss>

