All Apps and Add-ons

CHECK_MODE=xml doesn't work ?

sieutruc
Contributor

Hello,

When i indexed a XML file in local machine (Splunk version 5) with option CHECK_MODE=xml for sourtype "test_XML" , i saw clearly the fields that Splunk extracted, in the left hand, have the formats such as: table{@id} , table.content{@text} ...

But if i use splunk Universal Forwarder to forward that file to indexer (both have version 4.3.4), with CHECK_MODE=xml for that sourcetype, what i got in the left hand were : id, text... and i couldn't get any new field even using spath too. Can you tell me what is the problem ?

The file is just one-lien long xml format.

Tags (1)
0 Karma
1 Solution

sieutruc
Contributor

i don't know whether it's totally correct, when i upgrade all Splunk instances in my system \ to Version 5, all would be solved.

View solution in original post

0 Karma

sieutruc
Contributor

i don't know whether it's totally correct, when i upgrade all Splunk instances in my system \ to Version 5, all would be solved.

0 Karma
Get Updates on the Splunk Community!

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...