<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I extract fields from XML child and leaf nodes? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-extract-fields-from-XML-child-and-leaf-nodes/m-p/216598#M63574</link>
    <description>&lt;P&gt;Maybe try adding &lt;CODE&gt;KV_MODE = xml&lt;/CODE&gt; in your Search head &lt;CODE&gt;props.conf&lt;/CODE&gt;? &lt;/P&gt;</description>
    <pubDate>Tue, 03 Nov 2015 18:55:47 GMT</pubDate>
    <dc:creator>tmarlette</dc:creator>
    <dc:date>2015-11-03T18:55:47Z</dc:date>
    <item>
      <title>How do I extract fields from XML child and leaf nodes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-extract-fields-from-XML-child-and-leaf-nodes/m-p/216596#M63572</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;

&lt;P&gt;Splunk is pulling data from URLs , which is having below format:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;DocumentElement&amp;gt;
&amp;lt;CMN_DEPARTMENT&amp;gt;&amp;lt;id&amp;gt;DEP00001044&amp;lt;/id&amp;gt;&amp;lt;sys_id&amp;gt;0036651c6fffb000c60337c64f3ee4ac&amp;lt;/sys_id&amp;gt;&amp;lt;/CMN_DEPARTMENT&amp;gt;
&amp;lt;CMN_DEPARTMENT&amp;gt;&amp;lt;id&amp;gt;DEP00001045&amp;lt;/id&amp;gt;&amp;lt;sys_id&amp;gt;0036651c6fffb000c60337c64f3ee4ab&amp;lt;/sys_id&amp;gt;&amp;lt;/CMN_DEPARTMENT&amp;gt;
&amp;lt;CMN_DEPARTMENT&amp;gt;&amp;lt;id&amp;gt;DEP00001046&amp;lt;/id&amp;gt;&amp;lt;sys_id&amp;gt;0036651c6fffb000c60337c64f3ee4ad&amp;lt;/sys_id&amp;gt;&amp;lt;/CMN_DEPARTMENT&amp;gt;
&amp;lt;CMN_DEPARTMENT&amp;gt;&amp;lt;id&amp;gt;DEP00001047&amp;lt;/id&amp;gt;&amp;lt;sys_id&amp;gt;0036651c6fffb000c60337c64f3ee4ae&amp;lt;/sys_id&amp;gt;&amp;lt;/CMN_DEPARTMENT&amp;gt;
&amp;lt;CMN_DEPARTMENT&amp;gt;&amp;lt;id&amp;gt;DEP00001048&amp;lt;/id&amp;gt;&amp;lt;sys_id&amp;gt;0036651c6fffb000c60337c64f3ee4af&amp;lt;/sys_id&amp;gt;&amp;lt;/CMN_DEPARTMENT&amp;gt;
&amp;lt;CMN_DEPARTMENT&amp;gt;&amp;lt;id&amp;gt;DEP00001049&amp;lt;/id&amp;gt;&amp;lt;sys_id&amp;gt;0036651c6fffb000c60337c64f3ee4ag&amp;lt;/sys_id&amp;gt;&amp;lt;/CMN_DEPARTMENT&amp;gt;
&amp;lt;DocumentElement&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here DocumentElement is the root element, CMN_DEPARTMENT is child element and having "sys_id" are leaf nodes. When I extract index, I'm getting only one sys_id out of 5-6 ids under one event. Like this, we will have 24 events per day (i.e. pulling data from URL every one hour).&lt;/P&gt;

&lt;P&gt;How to extract each sys_id into index and perform search operations on it?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:47:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-extract-fields-from-XML-child-and-leaf-nodes/m-p/216596#M63572</guid>
      <dc:creator>SrinivasaC</dc:creator>
      <dc:date>2020-09-29T07:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do I extract fields from XML child and leaf nodes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-extract-fields-from-XML-child-and-leaf-nodes/m-p/216597#M63573</link>
      <description>&lt;P&gt;Have you tried using  the &lt;CODE&gt;xmlkv&lt;/CODE&gt; command ?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2015 18:47:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-extract-fields-from-XML-child-and-leaf-nodes/m-p/216597#M63573</guid>
      <dc:creator>aljohnson_splun</dc:creator>
      <dc:date>2015-11-03T18:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: How do I extract fields from XML child and leaf nodes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-extract-fields-from-XML-child-and-leaf-nodes/m-p/216598#M63574</link>
      <description>&lt;P&gt;Maybe try adding &lt;CODE&gt;KV_MODE = xml&lt;/CODE&gt; in your Search head &lt;CODE&gt;props.conf&lt;/CODE&gt;? &lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2015 18:55:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-extract-fields-from-XML-child-and-leaf-nodes/m-p/216598#M63574</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2015-11-03T18:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: How do I extract fields from XML child and leaf nodes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-extract-fields-from-XML-child-and-leaf-nodes/m-p/216599#M63575</link>
      <description>&lt;P&gt;Yes, we tried with xmlkv command &amp;amp; "KV_MODE = xml" in props.conf&lt;BR /&gt;
We are getting all the results as list basis not in event base means &lt;BR /&gt;
ex: 0036651c6fffb000c60337c64f3ee4ac&lt;BR /&gt;&lt;BR /&gt;
 0036651c6fffb000c60337c64f3ee4ab&lt;BR /&gt;&lt;BR /&gt;
0036651c6fffb000c60337c64f3ee4ad &lt;BR /&gt;
 0036651c6fffb000c60337c64f3ee4af&lt;BR /&gt;&lt;BR /&gt;
0036651c6fffb000c60337c64f3ee4ag&lt;/P&gt;

&lt;P&gt;Its whole result comes under one result (showing as list/values command).&lt;/P&gt;

&lt;P&gt;I need it as separate events.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 06:13:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-extract-fields-from-XML-child-and-leaf-nodes/m-p/216599#M63575</guid>
      <dc:creator>SrinivasaC</dc:creator>
      <dc:date>2015-11-04T06:13:56Z</dc:date>
    </item>
  </channel>
</rss>

