<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to filter out inline result in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460455#M191323</link>
    <description>&lt;P&gt;Thank you for your notice. Already updated. &lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2019 07:46:13 GMT</pubDate>
    <dc:creator>alivesince92</dc:creator>
    <dc:date>2019-08-23T07:46:13Z</dc:date>
    <item>
      <title>How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460453#M191321</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;After my query my result is: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;ns2:OriginCountry&amp;gt;RUS&amp;lt;/ns2:OriginCountry&amp;gt;&amp;lt;ns2:MessageValues&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;SendType&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;S&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;MessageCategory&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;S&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;ReceiverCountry&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;RUS&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;ReceiverLanguage&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;ru&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;OTP&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;736351&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;/ns2:MessageValues&amp;gt;&amp;lt;/ns2:NotificationRequest&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In my result I would like to receive only the figure between  &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;ns2:Value tags&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;How can I filter this out? &lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 07:27:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460453#M191321</guid>
      <dc:creator>alivesince92</dc:creator>
      <dc:date>2019-08-23T07:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460454#M191322</link>
      <description>&lt;P&gt;@alivesince92 &lt;/P&gt;

&lt;P&gt;We can not see your mentioned fields or XML tags. Can you please use &lt;CODE&gt;code&lt;/CODE&gt; block for that?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 07:34:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460454#M191322</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-08-23T07:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460455#M191323</link>
      <description>&lt;P&gt;Thank you for your notice. Already updated. &lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 07:46:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460455#M191323</guid>
      <dc:creator>alivesince92</dc:creator>
      <dc:date>2019-08-23T07:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460456#M191324</link>
      <description>&lt;P&gt;@alivesince92 &lt;/P&gt;

&lt;P&gt;You can use &lt;CODE&gt;spath&lt;/CODE&gt; here.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/spath"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/spath&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;YOUR_SEARCH  | spath | rename "ns2:MessageValues.ns2:MessageValue.ns2:Value" as Value | table Value
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Sample Search:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults | eval _raw="&amp;lt;ns2:OriginCountry&amp;gt;RUS&amp;lt;/ns2:OriginCountry&amp;gt;&amp;lt;ns2:MessageValues&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;SendType&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;S&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;MessageCategory&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;S&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;ReceiverCountry&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;RUS&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;ReceiverLanguage&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;ru&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;OTP&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;736351&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;/ns2:MessageValues&amp;gt;&amp;lt;/ns2:NotificationRequest&amp;gt;" | spath | rename "ns2:MessageValues.ns2:MessageValue.ns2:Value" as Value | table Value
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;AND if you want to display values in a different row then just add below search.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| mvexpand Value
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/mvexpand"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/mvexpand&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;UPDATED ANSWER&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;YOUR_SEARCH  | spath | rename "ns2:MessageValues.ns2:MessageValue.ns2:*" as * | eval temp = mvzip(Name,Value) | mvexpand temp | eval Name=mvindex(split(temp,","),0),Value=mvindex(split(temp,","),1) | table Name Value
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Sample Search:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults | eval _raw="&amp;lt;ns2:OriginCountry&amp;gt;RUS&amp;lt;/ns2:OriginCountry&amp;gt;&amp;lt;ns2:MessageValues&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;SendType&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;S&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;MessageCategory&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;S&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;ReceiverCountry&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;RUS&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;ReceiverLanguage&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;ru&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;OTP&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;736351&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;/ns2:MessageValues&amp;gt;&amp;lt;/ns2:NotificationRequest&amp;gt;" | spath | rename "ns2:MessageValues.ns2:MessageValue.ns2:*" as * | eval temp = mvzip(Name,Value) | mvexpand temp | eval Name=mvindex(split(temp,","),0),Value=mvindex(split(temp,","),1) | table Name Value
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;UPDATED ANSWER VERSION:2&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;As per your provided sample events I have made a few changes in my previous search.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;YOUR_SEARCH   | rex field=_raw "(?&amp;lt;data&amp;gt;&amp;lt;ns2:NotificationRequest(.+?)&amp;lt;\/ns2:NotificationRequest&amp;gt;)" 
    | eval _raw=data 
    | spath
    | rename "ns2:NotificationRequest.ns2:MessageValues.ns2:MessageValue.ns2:*" as * 
    | eval temp = mvzip(Name,Value) 
    | mvexpand temp 
    | eval Name=mvindex(split(temp,","),0),Value=mvindex(split(temp,","),1) 
    | table Name Value
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Sample Search:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval _raw="2019-08-28 10:37:32,511 [jetty-84 - /mobiliser/channel] ERROR com.***.***.***.***.project.jms.****liser S:METHOD_NAME=GwpVerifyPhone : WebAppSessionId= : ChannelSessionId=web-***-***-e8b8-***-8796-****365e : ClientIp=217117019234 : Corridor=[RU-UNKNOWN] - Message Sent successfully: &amp;lt;?xml version=\"1.0\" encoding=\"UTF-8\" standalone=\"yes\"?&amp;gt;&amp;lt;ns2:NotificationRequest xmlns:ns2=\"http://***\" xmlns:ns1=\"http://***\" xmlns:ns4=\"http://***\" xmlns:ns3=\"http://***\" xmlns:ns9=\"http://***\" xmlns:ns5=\"http://***\" xmlns:ns6=\"http://***\" xmlns:ns10=\"http://***\" xmlns:ns7=\"http://***\" xmlns:ns8=\"http://***\"&amp;gt;&amp;lt;ns1:Header&amp;gt;&amp;lt;ns1:Source&amp;gt;Wallet&amp;lt;/ns1:Source&amp;gt;&amp;lt;ns1:AppName ns1:Version=\"***\"&amp;gt;*DIGITAL&amp;lt;/ns1:AppName&amp;gt;&amp;lt;ns1:Timestamp&amp;gt;2019-08-28T10:37:29.898+03:00&amp;lt;/ns1:Timestamp&amp;gt;&amp;lt;ns1:CorrelationId&amp;gt;web-**-**-**-**-365e&amp;lt;/ns1:CorrelationId&amp;gt;&amp;lt;ns1:TransactionId&amp;gt;****&amp;lt;/ns1:TransactionId&amp;gt;&amp;lt;/ns1:Header&amp;gt;&amp;lt;ns3:Customer&amp;gt;&amp;lt;ns6:Address&amp;gt;&amp;lt;ns6:Country ns6:IS03=\"RUS\"/&amp;gt;&amp;lt;/ns6:Address&amp;gt;&amp;lt;ns7:Phone&amp;gt;&amp;lt;ns7:PhoneType ns7:Desc=\"MOBILE\"&amp;gt;MOBILE&amp;lt;/ns7:PhoneType&amp;gt;&amp;lt;ns7:PhoneNum ns7:ISDCode=\"7\"&amp;gt;9258487596&amp;lt;/ns7:PhoneNum&amp;gt;&amp;lt;/ns7:Phone&amp;gt;&amp;lt;ns10:Preference&amp;gt;&amp;lt;ns10:PrefLanguageCode&amp;gt;RU&amp;lt;/ns10:PrefLanguageCode&amp;gt;&amp;lt;/ns10:Preference&amp;gt;&amp;lt;/ns3:Customer&amp;gt;&amp;lt;ns2:MessageType&amp;gt;5010&amp;lt;/ns2:MessageType&amp;gt;&amp;lt;ns2:MessageChannelPreference&amp;gt;SMS&amp;lt;/ns2:MessageChannelPreference&amp;gt;&amp;lt;ns2:OriginCountry&amp;gt;RUS&amp;lt;/ns2:OriginCountry&amp;gt;&amp;lt;ns2:MessageValues&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;SendType&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;S&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;MessageCategory&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;S&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;ReceiverCountry&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;RUS&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;ReceiverLanguage&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;ru&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;OTP&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;342719&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;/ns2:MessageValues&amp;gt;&amp;lt;/ns2:NotificationRequest&amp;gt;" 
| rex field=_raw "(?&amp;lt;data&amp;gt;&amp;lt;ns2:NotificationRequest(.+?)&amp;lt;\/ns2:NotificationRequest&amp;gt;)" 
| eval _raw=data 
| spath
| rename "ns2:NotificationRequest.ns2:MessageValues.ns2:MessageValue.ns2:*" as * 
| eval temp = mvzip(Name,Value) 
| mvexpand temp 
| eval Name=mvindex(split(temp,","),0),Value=mvindex(split(temp,","),1) 
| table Name Value
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Happy Splunking&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 09:04:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460456#M191324</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-08-23T09:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460457#M191325</link>
      <description>&lt;P&gt;Thank you for your response, @kamlesh_vaghela , unfortunately it does not work as expected. I forgot to mention, that these 6 digits is variable, depending on the search. In this exact case my search consists of Phone number and Method name. expected result is OTP in ns2:Value field. &lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 12:57:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460457#M191325</guid>
      <dc:creator>alivesince92</dc:creator>
      <dc:date>2019-08-27T12:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460458#M191326</link>
      <description>&lt;P&gt;@alivesince92 &lt;BR /&gt;
 Please check my &lt;STRONG&gt;UPDATED ANSWER&lt;/STRONG&gt; .&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 13:29:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460458#M191326</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-08-27T13:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460459#M191327</link>
      <description>&lt;P&gt;@kamlesh_vaghela , it still does not work. &lt;BR /&gt;
Result I am getting in Verbose mode is empty table: &lt;BR /&gt;
&lt;A href="https://ibb.co/z6YS74x"&gt;https://ibb.co/z6YS74x&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 13:52:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460459#M191327</guid>
      <dc:creator>alivesince92</dc:creator>
      <dc:date>2019-08-27T13:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460460#M191328</link>
      <description>&lt;P&gt;@alivesince92&lt;/P&gt;

&lt;P&gt;Can you please share your search??  Please mask confidential value in search.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 04:45:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460460#M191328</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-08-28T04:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460461#M191329</link>
      <description>&lt;P&gt;My original search is &lt;CODE&gt;9258487596 "S:METHOD_NAME=GwpVerifyPhone"&lt;/CODE&gt;&lt;BR /&gt;
Response that I am getting: &lt;BR /&gt;
    &lt;CODE&gt;2019-08-28 10:37:32,511 [jetty-84 - /mobiliser/channel] ERROR com.***.***.***.***.project.jms.****liser S:METHOD_NAME=GwpVerifyPhone : WebAppSessionId= : ChannelSessionId=web-***-***-e8b8-***-8796-****365e : ClientIp=217117019234 : Corridor=[RU-UNKNOWN] - Message Sent successfully: &amp;lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&amp;gt;&amp;lt;ns2:NotificationRequest xmlns:ns2="http://***" xmlns:ns1="http://***" xmlns:ns4="http://***" xmlns:ns3="http://***" xmlns:ns9="http://***" xmlns:ns5="http://***" xmlns:ns6="http://***" xmlns:ns10="http://***" xmlns:ns7="http://***" xmlns:ns8="http://***"&amp;gt;&amp;lt;ns1:Header&amp;gt;&amp;lt;ns1:Source&amp;gt;Wallet&amp;lt;/ns1:Source&amp;gt;&amp;lt;ns1:AppName ns1:Version="***"&amp;gt;*DIGITAL&amp;lt;/ns1:AppName&amp;gt;&amp;lt;ns1:Timestamp&amp;gt;2019-08-28T10:37:29.898+03:00&amp;lt;/ns1:Timestamp&amp;gt;&amp;lt;ns1:CorrelationId&amp;gt;web-**-**-**-**-365e&amp;lt;/ns1:CorrelationId&amp;gt;&amp;lt;ns1:TransactionId&amp;gt;****&amp;lt;/ns1:TransactionId&amp;gt;&amp;lt;/ns1:Header&amp;gt;&amp;lt;ns3:Customer&amp;gt;&amp;lt;ns6:Address&amp;gt;&amp;lt;ns6:Country ns6:IS03="RUS"/&amp;gt;&amp;lt;/ns6:Address&amp;gt;&amp;lt;ns7:Phone&amp;gt;&amp;lt;ns7:PhoneType ns7:Desc="MOBILE"&amp;gt;MOBILE&amp;lt;/ns7:PhoneType&amp;gt;&amp;lt;ns7:PhoneNum ns7:ISDCode="7"&amp;gt;9258487596&amp;lt;/ns7:PhoneNum&amp;gt;&amp;lt;/ns7:Phone&amp;gt;&amp;lt;ns10:Preference&amp;gt;&amp;lt;ns10:PrefLanguageCode&amp;gt;RU&amp;lt;/ns10:PrefLanguageCode&amp;gt;&amp;lt;/ns10:Preference&amp;gt;&amp;lt;/ns3:Customer&amp;gt;&amp;lt;ns2:MessageType&amp;gt;5010&amp;lt;/ns2:MessageType&amp;gt;&amp;lt;ns2:MessageChannelPreference&amp;gt;SMS&amp;lt;/ns2:MessageChannelPreference&amp;gt;&amp;lt;ns2:OriginCountry&amp;gt;RUS&amp;lt;/ns2:OriginCountry&amp;gt;&amp;lt;ns2:MessageValues&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;SendType&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;S&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;MessageCategory&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;S&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;ReceiverCountry&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;RUS&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;ReceiverLanguage&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;ru&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;ns2:MessageValue&amp;gt;&amp;lt;ns2:Name&amp;gt;OTP&amp;lt;/ns2:Name&amp;gt;&amp;lt;ns2:Value&amp;gt;342719&amp;lt;/ns2:Value&amp;gt;&amp;lt;/ns2:MessageValue&amp;gt;&amp;lt;/ns2:MessageValues&amp;gt;&amp;lt;/ns2:NotificationRequest&amp;gt;&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;And all i need to be visible instead of all this response is 6 digits between ns2:Value fields. In this case - 342719, but as I mentioned before this is variable and it changes, as OTP is generated by the system &lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 07:43:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460461#M191329</guid>
      <dc:creator>alivesince92</dc:creator>
      <dc:date>2019-08-28T07:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460462#M191330</link>
      <description>&lt;P&gt;@alivesince92&lt;BR /&gt;
Please check my &lt;STRONG&gt;UPDATED ANSWER VERSION:2&lt;/STRONG&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  &lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 09:11:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460462#M191330</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-08-28T09:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460463#M191331</link>
      <description>&lt;P&gt;@kamlesh_vaghela you are the superstar! Thank You! &lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 12:45:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460463#M191331</guid>
      <dc:creator>alivesince92</dc:creator>
      <dc:date>2019-08-28T12:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out inline result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460464#M191332</link>
      <description>&lt;P&gt;@alivesince92&lt;/P&gt;

&lt;P&gt;Glad to help you. Please upvote any comments which help you to understand the solution and accept this answer to close this question. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Happy Splunking&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 04:46:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-out-inline-result/m-p/460464#M191332</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-08-29T04:46:35Z</dc:date>
    </item>
  </channel>
</rss>

