<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to create a dashboard of XML file? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/638799#M221334</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have the following event (XML) in Splunk, how can I create a dashboard of this XML?&lt;/P&gt;
&lt;P&gt;&amp;lt;JOB&lt;BR /&gt;APPLICATION="AFT-DTA"&lt;BR /&gt;CREATION_DATE="20191119"&lt;BR /&gt;JOBNAME="T-JOBA"&lt;BR /&gt;NODEID="10067"&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-ACCOUNT" VALUE="FIC+DBD"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LOSTYPE" VALUE="Unix"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-CONNTYPE1" VALUE="SFTP"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LHOST" VALUE="61021"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LUSER" VALUE="aft"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-ROSTYPE" VALUE="Windows"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RHOST" VALUE="dbd7006"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RUSER" VALUE="aftp"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LPATH1" VALUE="DIRA"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RPATH1" VALUE="DIRB"/&amp;gt;&lt;BR /&gt;&amp;lt;/JOB&amp;gt;&lt;BR /&gt;&amp;lt;JOB&lt;BR /&gt;APPLICATION="AFT-DTA"&lt;BR /&gt;CREATION_DATE="20200113"&lt;BR /&gt;JOBNAME="A-JOBB"&lt;BR /&gt;NODEID="10007"&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-ACCOUNT" VALUE="SDP+FIC"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LOSTYPE" VALUE="Unix"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-CONNTYPE1" VALUE="SFTP"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LHOST" VALUE="sdp9009"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LUSER" VALUE="aftp"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-ROSTYPE" VALUE="Unix"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-CONNTYPE2" VALUE="SFTP"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RHOST" VALUE="61021"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RUSER" VALUE="aft"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LPATH1" VALUE="DIRA"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RPATH1" VALUE="DIRB"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LPATH2" VALUE="DIRC"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RPATH2" VALUE="DIRD"/&amp;gt;&lt;BR /&gt;&amp;lt;/JOB&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Table should look like:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;ENV&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;JOBNAME&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;NODEID&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;LCON&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;LHOST&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;LPATH&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;RCON&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;RHOST&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;RPATH&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;TST&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;T-JOBA&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;10067&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;FIC&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;61021&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;DIRA&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;DBD&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;dbd7006&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;DIRB&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;ACC&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;A-JOBB&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;10007&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;SDP&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;sdp9009&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;
&lt;P&gt;DIRA&lt;BR /&gt;DIRC&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;FIC&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;61021&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;DIRB&lt;BR /&gt;DIRC&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where ENV depends on first letter of JOBNAME&lt;/P&gt;
&lt;P&gt;Where LCON is the value of&amp;nbsp;FTP-ACCOUNT" before the + sign.&lt;BR /&gt;Where RCON is the value of&amp;nbsp;FTP-ACCOUNT" after the + sign.&lt;/P&gt;
&lt;P&gt;LPATH / RPATH can have multiple values where&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Apr 2023 19:05:33 GMT</pubDate>
    <dc:creator>ns102</dc:creator>
    <dc:date>2023-04-06T19:05:33Z</dc:date>
    <item>
      <title>How to create a dashboard of XML file?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/638799#M221334</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have the following event (XML) in Splunk, how can I create a dashboard of this XML?&lt;/P&gt;
&lt;P&gt;&amp;lt;JOB&lt;BR /&gt;APPLICATION="AFT-DTA"&lt;BR /&gt;CREATION_DATE="20191119"&lt;BR /&gt;JOBNAME="T-JOBA"&lt;BR /&gt;NODEID="10067"&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-ACCOUNT" VALUE="FIC+DBD"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LOSTYPE" VALUE="Unix"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-CONNTYPE1" VALUE="SFTP"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LHOST" VALUE="61021"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LUSER" VALUE="aft"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-ROSTYPE" VALUE="Windows"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RHOST" VALUE="dbd7006"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RUSER" VALUE="aftp"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LPATH1" VALUE="DIRA"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RPATH1" VALUE="DIRB"/&amp;gt;&lt;BR /&gt;&amp;lt;/JOB&amp;gt;&lt;BR /&gt;&amp;lt;JOB&lt;BR /&gt;APPLICATION="AFT-DTA"&lt;BR /&gt;CREATION_DATE="20200113"&lt;BR /&gt;JOBNAME="A-JOBB"&lt;BR /&gt;NODEID="10007"&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-ACCOUNT" VALUE="SDP+FIC"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LOSTYPE" VALUE="Unix"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-CONNTYPE1" VALUE="SFTP"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LHOST" VALUE="sdp9009"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LUSER" VALUE="aftp"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-ROSTYPE" VALUE="Unix"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-CONNTYPE2" VALUE="SFTP"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RHOST" VALUE="61021"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RUSER" VALUE="aft"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LPATH1" VALUE="DIRA"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RPATH1" VALUE="DIRB"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-LPATH2" VALUE="DIRC"/&amp;gt;&lt;BR /&gt;&amp;lt;VARIABLE NAME="%%FTP-RPATH2" VALUE="DIRD"/&amp;gt;&lt;BR /&gt;&amp;lt;/JOB&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Table should look like:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;ENV&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;JOBNAME&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;NODEID&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;LCON&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;LHOST&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;LPATH&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;RCON&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;RHOST&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;RPATH&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;TST&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;T-JOBA&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;10067&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;FIC&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;61021&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;DIRA&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;DBD&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;dbd7006&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;DIRB&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;ACC&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;A-JOBB&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;10007&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;SDP&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;sdp9009&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;
&lt;P&gt;DIRA&lt;BR /&gt;DIRC&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;FIC&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;61021&lt;/TD&gt;
&lt;TD width="11.11111111111111%" height="24px"&gt;DIRB&lt;BR /&gt;DIRC&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where ENV depends on first letter of JOBNAME&lt;/P&gt;
&lt;P&gt;Where LCON is the value of&amp;nbsp;FTP-ACCOUNT" before the + sign.&lt;BR /&gt;Where RCON is the value of&amp;nbsp;FTP-ACCOUNT" after the + sign.&lt;/P&gt;
&lt;P&gt;LPATH / RPATH can have multiple values where&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 19:05:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/638799#M221334</guid>
      <dc:creator>ns102</dc:creator>
      <dc:date>2023-04-06T19:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dashboard of XML file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/638802#M221336</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255570"&gt;@ns102&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What have you tried so far?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 09:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/638802#M221336</guid>
      <dc:creator>Gr0und_Z3r0</dc:creator>
      <dc:date>2023-04-05T09:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dashboard of XML file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/638852#M221358</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Not much &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; I'm new to Splunk and really struggling to add &amp;lt;VARIABLE NAME&amp;gt; to my output.&lt;BR /&gt;At the moment I have the following. So that's quite basic;&lt;/P&gt;&lt;P&gt;&amp;nbsp;| table DEFTABLE.FOLDER.JOB* |&lt;BR /&gt;rename DEFTABLE.FOLDER.JOB{@*} as * |&lt;BR /&gt;eval temp=mvzip(JOBNAME,mvzip(NODEID,APPLICATION,"&amp;amp;"),"&amp;amp;")&lt;BR /&gt;| table temp&lt;BR /&gt;| mvexpand temp&lt;BR /&gt;| rex field=temp "(?&amp;lt;JOBNAME&amp;gt;.*)&amp;amp;(?&amp;lt;NODEID&amp;gt;.*)&amp;amp;(?&amp;lt;APPLICATION&amp;gt;.*)" | fields - temp&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 14:59:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/638852#M221358</guid>
      <dc:creator>ns102</dc:creator>
      <dc:date>2023-04-05T14:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dashboard of XML file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/638950#M221401</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255570"&gt;@ns102&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;To get you started,&amp;nbsp; here is something you can do to achieve a table of information you want.&lt;BR /&gt;There'll be better ways to do it, but this yields what you are after.&lt;BR /&gt;&lt;BR /&gt;This is assuming, you are seeing 2 jobs as a single event. Ideally, each job should be treated as a separate event with its own timestamp. This can be done by updating the sourcetype configuration in props.conf, as part of the data ingestion process.&lt;BR /&gt;Secondly, to speed things up I would suggest extracting fields during ingestion period, rather than doing it on search time.&amp;nbsp;&lt;BR /&gt;For the ENV value, I would suggest creating a lookup, that checks the jobname and returns the environment value. Furthermore, you can setup an automatic lookup so that ENV field is already present even during search time. This way you can just update and maintain the lookup values to accommodate more environments and jobs as and when you have.&lt;BR /&gt;&lt;BR /&gt;Also, while building dashboards I would recommend building a base-search and using those to get primary set of information to design panels and get insights out of. It will reduce the number of searches with field extractions and get you results as fast as it could.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;source="xml.log" host="Beast" sourcetype="test-xml" 
| rex field=_raw "APPLICATION\=\"(?P&amp;lt;app&amp;gt;.*)\"" 
| rex mode=sed "s/[\r\n]+/ /g" 
| rex mode=sed "s/[\%]+//g" 
| eval job=trim(split(_raw,"&amp;lt;JOB")) 
| fields _time job 
| stats values(_time) as _time by job 
| rex field=job "JOBNAME=\"(?P&amp;lt;JOBNAME&amp;gt;[\w\-]+)" 
| rex field=job "NODEID=\"(?P&amp;lt;NODEID&amp;gt;[\w\-]+)" 
| rex field=job "FTP\-ACCOUNT\"\sVALUE\=\"(?P&amp;lt;LCON&amp;gt;[\w]+)\+(?P&amp;lt;RCON&amp;gt;[\w]+)" 
| rex field=job "FTP\-LHOST\"\sVALUE\=\"(?P&amp;lt;LHOST&amp;gt;[\w]+)" 
| rex field=job "FTP\-RHOST\"\sVALUE\=\"(?P&amp;lt;RHOST&amp;gt;[\w]+)" 
| rex field=job "FTP-LPATH1\"\sVALUE\=\"(?P&amp;lt;LPATH1&amp;gt;[\w]+)\"\/\&amp;gt;\s\&amp;lt;VARIABLE\sNAME\=\"FTP-RPATH1\"\sVALUE\=\"(?P&amp;lt;RPATH1&amp;gt;[\w]+)\"\/\&amp;gt;" 
| rex field=job "FTP-LPATH2\"\sVALUE\=\"(?P&amp;lt;LPATH2&amp;gt;[\w]+)\"\/\&amp;gt;\s\&amp;lt;VARIABLE\sNAME\=\"FTP-RPATH2\"\sVALUE\=\"(?P&amp;lt;RPATH2&amp;gt;[\w]+)\"\/\&amp;gt;" 
| fillnull LPATH2,RPATH2 value=null 
| eval LPATH = LPATH1+","+LPATH2 
| eval LPATH =replace(LPATH,",null","") 
| eval RPATH = RPATH1+","+RPATH2 
| eval RPATH =replace(RPATH,",null","") 
| eval ENV=if(JOBNAME="T-JOBA","TST",if(JOBNAME="A-JOBB","ACC","OTHER_ENV")) 
| table ENV JOBNAME NODEID LCON LHOST LPATH RCON RHOST RPATH 
| where isnotnull(JOBNAME)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gr0und_Z3r0_0-1680761059846.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24806i25B984BF0B231620/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Gr0und_Z3r0_0-1680761059846.png" alt="Gr0und_Z3r0_0-1680761059846.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;~ If the reply helps, an upvote would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 06:04:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/638950#M221401</guid>
      <dc:creator>Gr0und_Z3r0</dc:creator>
      <dc:date>2023-04-06T06:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dashboard of XML file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/638981#M221408</link>
      <description>&lt;P&gt;Wow, I can really go further with this and when I get more experience with Splunk I will make improvements. for now it's a perfect ! Thank you so much!&lt;/P&gt;&lt;P&gt;LPATH and RPATH are still empty&amp;nbsp; but that's because the value can also contain / _ and \ characters. hopefully I'll can figure this out.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 09:01:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/638981#M221408</guid>
      <dc:creator>ns102</dc:creator>
      <dc:date>2023-04-06T09:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a dashboard of XML file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/639056#M221431</link>
      <description>&lt;P&gt;Your Q is truncated so I could not do everything but this should get you far enough to finish:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval _raw="&amp;lt;JOB
APPLICATION=\"AFT-DTA\"
CREATION_DATE=\"20191119\"
JOBNAME=\"T-JOBA\"
NODEID=\"10067\"
&amp;lt;VARIABLE NAME=\"%%FTP-ACCOUNT\" VALUE=\"FIC+DBD\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-LOSTYPE\" VALUE=\"Unix\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-CONNTYPE1\" VALUE=\"SFTP\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-LHOST\" VALUE=\"61021\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-LUSER\" VALUE=\"aft\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-ROSTYPE\" VALUE=\"Windows\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-RHOST\" VALUE=\"dbd7006\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-RUSER\" VALUE=\"aftp\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-LPATH1\" VALUE=\"DIRA\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-RPATH1\" VALUE=\"DIRB\"/&amp;gt;
&amp;lt;/JOB&amp;gt;
&amp;lt;JOB
APPLICATION=\"AFT-DTA\"
CREATION_DATE=\"20200113\"
JOBNAME=\"A-JOBB\"
NODEID=\"10007\"
&amp;lt;VARIABLE NAME=\"%%FTP-ACCOUNT\" VALUE=\"SDP+FIC\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-LOSTYPE\" VALUE=\"Unix\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-CONNTYPE1\" VALUE=\"SFTP\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-LHOST\" VALUE=\"sdp9009\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-LUSER\" VALUE=\"aftp\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-ROSTYPE\" VALUE=\"Unix\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-CONNTYPE2\" VALUE=\"SFTP\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-RHOST\" VALUE=\"61021\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-RUSER\" VALUE=\"aft\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-LPATH1\" VALUE=\"DIRA\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-RPATH1\" VALUE=\"DIRB\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-LPATH2\" VALUE=\"DIRC\"/&amp;gt;
&amp;lt;VARIABLE NAME=\"%%FTP-RPATH2\" VALUE=\"DIRD\"/&amp;gt;
&amp;lt;/JOB&amp;gt;"
| rename COMMENT AS "EVERYTHING ABOVE IS CREATING FAKE DATA; EVERYTHING BELOW IS YOUR SOLUTION"
| rex field=_raw mode=sed "s/\&amp;lt;VARIABLE NAME=\"//g s/\"\s+VALUE=/=/g s/\/&amp;gt;//g"
| kv
| rex field=JOBNAME "^(?&amp;lt;ENV&amp;gt;\w+)-(?&amp;lt;JOBNAME&amp;gt;.*)$"
| rex field=FTP_ACCOUNT "^(?&amp;lt;LCON&amp;gt;[^+]+)\+(?&amp;lt;RCON&amp;gt;.*)$"
| eval LPATH="" | foreach FTP_LPATH* [ eval LPATH=mvappend(LPATH, &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;) | fields - &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; ]
| eval RPATH="" | foreach FTP_RPATH* [ eval RPATH=mvappend(RPATH, &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;) | fields - &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; ]
| eval LHOST="" | foreach FTP_LHOST* [ eval LHOST=mvappend(LHOST, &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;) | fields - &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; ]
| eval RHOST="" | foreach FTP_RHOST* [ eval RHOST=mvappend(RHOST, &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;) | fields - &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; ]
| table ENV JOBNAME NODEID LCON LHOST LPATH RCON RHOST RPATH TST T-JOBA 10067 FIC 61021 DIRA DBD dbd7006 DIRB ACC A-JOBB 10007 SDP sdp9009 *&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 06 Apr 2023 18:03:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-dashboard-of-XML-file/m-p/639056#M221431</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-04-06T18:03:48Z</dc:date>
    </item>
  </channel>
</rss>

