<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multivalued field mapping issue from an nested XML source in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Multivalued-field-mapping-issue-from-an-nested-XML-source/m-p/599081#M208580</link>
    <description>&lt;LI-CODE lang="markup"&gt;| spath output=workstationNumber path=WorkstationMetrics.WorkstationMetricData{@WorkstationID}
| spath output=workstationData path=WorkstationMetrics.WorkstationMetricData
| fields - _raw
| eval workstation=mvzip(workstationNumber, workstationData,"|")
| mvexpand workstation
| eval workstationNumber=mvindex(split(workstation,"|"),0)
| eval workstationData=mvindex(split(workstation,"|"),1)
| spath output=sequenceType input=workstationData path=SequenceNumberValue{@TypeCode}
| spath output=sequenceNumber input=workstationData path=SequenceNumberValue
| eval typevalue=mvzip(sequenceType, sequenceNumber,"|")
| mvexpand typevalue
| eval sequenceType=mvindex(split(typevalue,"|"),0)
| eval sequenceNumber=mvindex(split(typevalue,"|"),1)
| fields - workstation workstationData typevalue&lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 24 May 2022 13:27:33 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2022-05-24T13:27:33Z</dc:date>
    <item>
      <title>Multivalued field mapping issue from an nested XML source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalued-field-mapping-issue-from-an-nested-XML-source/m-p/599072#M208579</link>
      <description>&lt;P&gt;Hello Splunkers!&lt;/P&gt;&lt;P&gt;I have an issue in grouping multivalued field after extracting fields from nested xml. The sample is as follows,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; &amp;lt;WorkstationMetrics xmlns=“xxxxxxxx”&amp;gt;
                    &amp;lt;WorkstationMetricData TypeCode="None" WorkstationID="0"&amp;gt;
                      &amp;lt;SequenceNumberValue Timestamp="2022-05-1" TypeCode="First"&amp;gt;15704&amp;lt;/SequenceNumberValue&amp;gt;
                      &amp;lt;SequenceNumberValue Timestamp="2022-05-1" TypeCode="Last"&amp;gt;15710&amp;lt;/SequenceNumberValue&amp;gt;
                    &amp;lt;/WorkstationMetricData&amp;gt;
                    &amp;lt;WorkstationMetricData TypeCode="Manual" WorkstationID="03"&amp;gt;
                      &amp;lt;SequenceNumberValue Timestamp="2022-05-1" TypeCode="First"&amp;gt;9395&amp;lt;/SequenceNumberValue&amp;gt;
                      &amp;lt;SequenceNumberValue Timestamp="2022-05-1" TypeCode="Last"&amp;gt;9463&amp;lt;/SequenceNumberValue&amp;gt;
                    &amp;lt;/WorkstationMetricData&amp;gt;
                    &amp;lt;WorkstationMetricData TypeCode="Manual" WorkstationID="05"&amp;gt;
                      &amp;lt;SequenceNumberValue Timestamp="2022-05-1" TypeCode="First"&amp;gt;62&amp;lt;/SequenceNumberValue&amp;gt;
                      &amp;lt;SequenceNumberValue Timestamp="2022-05-1" TypeCode="Last"&amp;gt;297&amp;lt;/SequenceNumberValue&amp;gt;
                    &amp;lt;/WorkstationMetricData&amp;gt;
                  &amp;lt;/WorkstationMetrics&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;I tried with following search query to&amp;nbsp; extract field. But the fields extracted are multivalued with &lt;FONT color="#FF0000"&gt;&lt;U&gt;varying&lt;/U&gt;&lt;/FONT&gt; &lt;U&gt;&lt;FONT color="#FF0000"&gt;cardinality&lt;/FONT&gt;&lt;/U&gt; and hence some of my &lt;U&gt;&lt;FONT color="#FF0000"&gt;mvzip&lt;/FONT&gt;&lt;/U&gt; commands are not working as expected. Please find below my search query for your reference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=... sourcetype=...
| spath output=workstationNumber path=WorkstationMetrics.WorkstationMetricData{@WorkstationID}
| spath output=sequenceType path=WorkstationMetrics.WorkstationMetricData.SequenceNumberValue{@TypeCode}
| spath output=sequenceNumber path=WorkstationMetrics.WorkstationMetricData.SequenceNumberValue
| eval consolidate=mvzip(sequenceType,sequenceNumber)
| mvexpand consolidate
| eval temp=split(consolidate,","), type=mvindex(temp,0), seqno=mvindex(temp,1)
| table workstationNumber type seqno&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;I expect to present this data in following format, could some one&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="32.92326537754834%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="10%" height="25px"&gt;&lt;STRONG&gt;Sl.no&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;&lt;STRONG&gt;WorkstationID&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;&lt;STRONG&gt;TypeCode&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;&lt;STRONG&gt;SequenceNumberValue&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="47px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;First&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;15704&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="47px"&gt;2&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;0&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;Last&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;15710&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P class=""&gt;Any help in mapping 2 multivalued fields with varying cardinality would resolve this issue. Or do we need think out of box?&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 13:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalued-field-mapping-issue-from-an-nested-XML-source/m-p/599072#M208579</guid>
      <dc:creator>sundarrajan</dc:creator>
      <dc:date>2022-05-24T13:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalued field mapping issue from an nested XML source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalued-field-mapping-issue-from-an-nested-XML-source/m-p/599081#M208580</link>
      <description>&lt;LI-CODE lang="markup"&gt;| spath output=workstationNumber path=WorkstationMetrics.WorkstationMetricData{@WorkstationID}
| spath output=workstationData path=WorkstationMetrics.WorkstationMetricData
| fields - _raw
| eval workstation=mvzip(workstationNumber, workstationData,"|")
| mvexpand workstation
| eval workstationNumber=mvindex(split(workstation,"|"),0)
| eval workstationData=mvindex(split(workstation,"|"),1)
| spath output=sequenceType input=workstationData path=SequenceNumberValue{@TypeCode}
| spath output=sequenceNumber input=workstationData path=SequenceNumberValue
| eval typevalue=mvzip(sequenceType, sequenceNumber,"|")
| mvexpand typevalue
| eval sequenceType=mvindex(split(typevalue,"|"),0)
| eval sequenceNumber=mvindex(split(typevalue,"|"),1)
| fields - workstation workstationData typevalue&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 24 May 2022 13:27:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalued-field-mapping-issue-from-an-nested-XML-source/m-p/599081#M208580</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-05-24T13:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalued field mapping issue from an nested XML source</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalued-field-mapping-issue-from-an-nested-XML-source/m-p/599151#M208590</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;! It even works over a large dataset with multiple lines. A clear out-of box view, of taking the portion of event as a field and piping to rex&amp;nbsp; the relevant field.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 18:45:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalued-field-mapping-issue-from-an-nested-XML-source/m-p/599151#M208590</guid>
      <dc:creator>sundarrajan</dc:creator>
      <dc:date>2022-05-24T18:45:11Z</dc:date>
    </item>
  </channel>
</rss>

