All Apps and Add-ons

Parse an XML in splunk events

p0p00aj
New Member

I have data coming in to splunk from a SQL Table and one of the columns in the table has a XML. Is there a way we can parse that XML and extract fields in splunk??

The XML is not always the same and keeps changing

0 Karma

woodcock
Esteemed Legend

If you can remove the cruft and ensure that the entire raw event is XML, then you can set KV_MODE to xml and it will automatically do dynamic field extraction. Short of that, you can do it manually using xpath:
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Xpath

0 Karma

p0p00aj
New Member

XMLKV command is more useful in this scenario. it automatically pulls all the xml fields and indexes them.

0 Karma

efavreau
Motivator

Look into the xpath command: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Xpath

###

If this reply helps you, an upvote would be appreciated.
0 Karma

p0p00aj
New Member

Thanks for your message. I see xmlkv more useful for this scenario where the xml fields are automatically pulled.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...