I am using Splunk TA for Windows infrastructure configured to consume the XML logs.
The problem is the RAW doesn't parse out the XML that is contained w/in the XML log very well (see raw output below)
It parses the "Outer" XML fine, but the "Inner" XML, not so much. (See all the lt; and gt;) > and < is just to get through this WYSIWYG editor
Anyone have good advice on how to get splunk to parse and store this properly?
<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'>
<Provider Name='AD FS Auditing'/>
<EventID Qualifiers='0'>1200</EventID>
<TimeCreated SystemTime='2020-05-31T20:31:28.875321100Z'/>
<Security UserID='S-1-5-21----SID'/>
<Data>&lt;?xml version="1.0" encoding="utf-16"?&gt;
&lt;AuditBase xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="AppTokenAudit"&gt;
&lt;Component xsi:type="ResourceAuditComponent"&gt;
&lt;ClaimsProvider&gt;AD AUTHORITY&lt;/ClaimsProvider&gt;
&lt;Component xsi:type="AuthNAuditComponent"&gt;
&lt;Component xsi:type="ProtocolAuditComponent"&gt;
&lt;Component xsi:type="RequestAuditComponent"&gt;
&lt;ForwardedIpAddress /&gt;
&lt;UserAgentString&gt;Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko&lt;/UserAgentString&gt;
Option 1:
I have an admin on demand ticket open for this right now, did you ever get resolution?
I'm running into the same problem. Was there a resolution to this?
I have the same problem. Did you find a solution?
I have the same problem.
Only on ADFS audit logs, maybe something to change on the windows server directly instead of touching splunk here?
@samsonusmc ,
Use spath command to extarct field-