<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XML field extraction with spath in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/XML-field-extraction-with-spath/m-p/536010#M151526</link>
    <description>&lt;P&gt;Excellent! Thank you so much!&lt;/P&gt;</description>
    <pubDate>Fri, 15 Jan 2021 14:21:42 GMT</pubDate>
    <dc:creator>4uramana4u</dc:creator>
    <dc:date>2021-01-15T14:21:42Z</dc:date>
    <item>
      <title>XML field extraction with spath</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-field-extraction-with-spath/m-p/535957#M151507</link>
      <description>&lt;P&gt;eval FunctionalRef=spath(_raw,"n2:EvtMsg.Bd.BOEvt.Evt.DatElGrp{2}.DatEl.Val") -&amp;gt; I am getting two(2) values&amp;nbsp;DHL5466256965140262WH3,&amp;nbsp;DE4608089.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Instead I should get only&amp;nbsp;DHL5466256965140262WH3.&amp;nbsp; So this value is not static&lt;/P&gt;&lt;P&gt;XML Snippet:&lt;/P&gt;&lt;P&gt;&amp;lt;DatElGrp Cd="CommonGrp"&amp;gt;&lt;BR /&gt;&amp;lt;DatEl&amp;gt;&lt;BR /&gt;&amp;lt;Cd&amp;gt;FunctionalRef&amp;lt;/Cd&amp;gt;&lt;BR /&gt;&amp;lt;Val&amp;gt;DHL5466256965140262WH3&amp;lt;/Val&amp;gt;&lt;BR /&gt;&amp;lt;/DatEl&amp;gt;&lt;BR /&gt;&amp;lt;DatEl&amp;gt;&lt;BR /&gt;&amp;lt;Cd&amp;gt;DeclarantID&amp;lt;/Cd&amp;gt;&lt;BR /&gt;&amp;lt;Val&amp;gt;DE4608089&amp;lt;/Val&amp;gt;&lt;BR /&gt;&amp;lt;/DatEl&amp;gt;&lt;BR /&gt;&amp;lt;/DatElGrp&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 07:44:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-field-extraction-with-spath/m-p/535957#M151507</guid>
      <dc:creator>4uramana4u</dc:creator>
      <dc:date>2021-01-15T07:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: XML field extraction with spath</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-field-extraction-with-spath/m-p/535999#M151521</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal | head 1 | fields _raw
| eval _raw="&amp;lt;DatElGrp Cd=\"CommonGrp\"&amp;gt;
&amp;lt;DatEl&amp;gt;
&amp;lt;Cd&amp;gt;FunctionalRef&amp;lt;/Cd&amp;gt;
&amp;lt;Val&amp;gt;DHL5466256965140262WH3&amp;lt;/Val&amp;gt;
&amp;lt;/DatEl&amp;gt;
&amp;lt;DatEl&amp;gt;
&amp;lt;Cd&amp;gt;DeclarantID&amp;lt;/Cd&amp;gt;
&amp;lt;Val&amp;gt;DE4608089&amp;lt;/Val&amp;gt;
&amp;lt;/DatEl&amp;gt;
&amp;lt;/DatElGrp&amp;gt;"
| spath
| rename DatElGrp{@Cd} as GrpCd, DatElGrp.* as *
| foreach DatEl.* [ eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; = mvindex('&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;' , 0)]&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 15 Jan 2021 12:44:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-field-extraction-with-spath/m-p/535999#M151521</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2021-01-15T12:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: XML field extraction with spath</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-field-extraction-with-spath/m-p/536007#M151525</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal | head 1 | fields _raw
| eval _raw="&amp;lt;DatElGrp Cd=\"CommonGrp\"&amp;gt;
&amp;lt;DatEl&amp;gt;
&amp;lt;Cd&amp;gt;FunctionalRef&amp;lt;/Cd&amp;gt;
&amp;lt;Val&amp;gt;DHL5466256965140262WH3&amp;lt;/Val&amp;gt;
&amp;lt;/DatEl&amp;gt;
&amp;lt;DatEl&amp;gt;
&amp;lt;Cd&amp;gt;DeclarantID&amp;lt;/Cd&amp;gt;
&amp;lt;Val&amp;gt;DE4608089&amp;lt;/Val&amp;gt;
&amp;lt;/DatEl&amp;gt;
&amp;lt;/DatElGrp&amp;gt;"
| spath DatElGrp.DatEl.Cd{1}
| spath DatElGrp.DatEl.Val{1}&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 15 Jan 2021 13:27:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-field-extraction-with-spath/m-p/536007#M151525</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2021-01-15T13:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: XML field extraction with spath</title>
      <link>https://community.splunk.com/t5/Splunk-Search/XML-field-extraction-with-spath/m-p/536010#M151526</link>
      <description>&lt;P&gt;Excellent! Thank you so much!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 14:21:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/XML-field-extraction-with-spath/m-p/536010#M151526</guid>
      <dc:creator>4uramana4u</dc:creator>
      <dc:date>2021-01-15T14:21:42Z</dc:date>
    </item>
  </channel>
</rss>

