- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk and SOAP
splunkit2010
Explorer
04-18-2013
09:07 AM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Paolo_Prigione
Builder
05-06-2013
12:05 PM
Splunk can index SOAP envelopes: they are just plain text. For instance, you could set jboss to trace the soap requests it is serving to file, then collect it with splunk.
You could assign that data a sourcetype which has the props.conf's **KV_MODE=xml** setting to automatically extract the fields at search time. Also, you could use multiple SEDCMD configs to strip the SOAP tags rightaway (unless you like to report on the xmlns you are using the most 🙂
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ayn
Legend
04-18-2013
09:39 AM
In which way were you thinking?
