All Apps and Add-ons

Why are you doing xml extractions manually via transforms?

dvb
Path Finder

In Splunk Add-on for Sysmon | Splunkbase (and some other Add-Ons) XML extractions are done via a lot of manual transforms (e.g. [sysmon-version] REGEX = <Version>(\d+)</Version> FORMAT = Version::$1). Why aren't you using KV_MODE = XML?

And could you please add the field query_type (Network_Resolution DM) and record_type values for A and AAAA records (which do NOT have a type: .. entry).

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I can't speak for the app's author, but one reason for using REGEX over KV_MODE is KV_MODE=xml only works on well-formed XML whereas REGEX often can extract fields from poorly-formatted XML events.

---
If this reply helps you, Karma would be appreciated.
0 Karma

dvb
Path Finder

Sorry, but I would like an answer from the author of the app (as I already know what you wrote).

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...