<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract multiple field values from XML in Splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-field-values-from-XML-in-Splunk/m-p/59936#M14752</link>
    <description>&lt;P&gt;Maybe you can update the XML to show what you are talking about.  Right now it's hard to tell why it's not working for you.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Dec 2012 19:47:45 GMT</pubDate>
    <dc:creator>sdaniels</dc:creator>
    <dc:date>2012-12-11T19:47:45Z</dc:date>
    <item>
      <title>Extract multiple field values from XML in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-field-values-from-XML-in-Splunk/m-p/59933#M14749</link>
      <description>&lt;P&gt;Hi, &lt;BR /&gt;
   Please advise the splunk search to extract multiple field values from the xml in splunk.&lt;BR /&gt;
   For example, how can I get both the user name and user id using the sample xml below.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;users&amp;gt;
  &amp;lt;user&amp;gt;
    &amp;lt;user_name&amp;gt;John Jobs&amp;lt;/user_name&amp;gt;
   &amp;lt;user_id&amp;gt;JJobs&amp;lt;/user_id&amp;gt;
   &amp;lt;user_iemail&amp;gt;JJobs@example.com&amp;lt;/user_email&amp;gt;
&amp;lt;/user&amp;gt;
 &amp;lt;user&amp;gt;
    &amp;lt;user_name&amp;gt;Mary Ann&amp;lt;/user_name&amp;gt;
   &amp;lt;user_id&amp;gt;mann&amp;lt;/user_id&amp;gt;
   &amp;lt;user_iemail&amp;gt;mann@outlook.com&amp;lt;/user_email&amp;gt;
 &amp;lt;/user&amp;gt;
&amp;lt;/users&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 11 Dec 2012 15:38:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-field-values-from-XML-in-Splunk/m-p/59933#M14749</guid>
      <dc:creator>shangshin</dc:creator>
      <dc:date>2012-12-11T15:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: Extract multiple field values from XML in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-field-values-from-XML-in-Splunk/m-p/59934#M14750</link>
      <description>&lt;P&gt;You can use the spath command to get the values that you want.  See the xml examples towards the bottom.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Spath"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Spath&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can also have Splunk extract all fields automatically for you:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/2889/automatically-extract-xml-key-value-pairs"&gt;http://splunk-base.splunk.com/answers/2889/automatically-extract-xml-key-value-pairs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2012 18:24:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-field-values-from-XML-in-Splunk/m-p/59934#M14750</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-12-11T18:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Extract multiple field values from XML in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-field-values-from-XML-in-Splunk/m-p/59935#M14751</link>
      <description>&lt;P&gt;Thank you! This is very helpful.&lt;/P&gt;

&lt;P&gt;I am able to extract most of the elements except for the element value with forward slash.&lt;/P&gt;

&lt;P&gt;E.g.&lt;BR /&gt;
the xml element below users.usr.url returns an empty value.&lt;BR /&gt;
&lt;URL&gt;/en-GB/app/search/flashtimeline?q=search sourcetype&lt;/URL&gt;&lt;/P&gt;

&lt;P&gt;Is there a special function for this?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2012 19:45:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-field-values-from-XML-in-Splunk/m-p/59935#M14751</guid>
      <dc:creator>shangshin</dc:creator>
      <dc:date>2012-12-11T19:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Extract multiple field values from XML in Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-field-values-from-XML-in-Splunk/m-p/59936#M14752</link>
      <description>&lt;P&gt;Maybe you can update the XML to show what you are talking about.  Right now it's hard to tell why it's not working for you.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2012 19:47:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-field-values-from-XML-in-Splunk/m-p/59936#M14752</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-12-11T19:47:45Z</dc:date>
    </item>
  </channel>
</rss>

