All Apps and Add-ons

Parse an XML in splunk events

p0p00aj
New Member

I have data coming in to splunk from a SQL Table and one of the columns in the table has a XML. Is there a way we can parse that XML and extract fields in splunk??

The XML is not always the same and keeps changing

0 Karma

woodcock
Esteemed Legend

If you can remove the cruft and ensure that the entire raw event is XML, then you can set KV_MODE to xml and it will automatically do dynamic field extraction. Short of that, you can do it manually using xpath:
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Xpath

0 Karma

p0p00aj
New Member

XMLKV command is more useful in this scenario. it automatically pulls all the xml fields and indexes them.

0 Karma

efavreau
Motivator

Look into the xpath command: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Xpath

###

If this reply helps you, an upvote would be appreciated.
0 Karma

p0p00aj
New Member

Thanks for your message. I see xmlkv more useful for this scenario where the xml fields are automatically pulled.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...