Here's a snippet of a long XML file. I would like to extract the keys such as id, status, error_sequence_number, etc. then assign the value as indicated by the string "value=".
You could try using the spath command:
http://docs.splunk.com/Documentation/Splunk/6.0.1/SearchReference/Spath
When defining field extractions for this sourcetype in transforms.conf you can use a regex like so:
[some_stanza]
...
REGEX = name="(?<_KEY_1>[^"]+)"\s+value="(?<_VAL_1>[^"]+)"
...
Note, you may want to define two of those if the order of name and value can be reversed in your data.