I know there has to be a nice way to do this upon indexing in Splunk...I have a large XML file that I am indexing on the tag info however when each event is index I want some information from higher up the "tree" of the XML to be placed into that event. For a small example in:
First off, your sample XML seem to have info end tags missing. You can use spath or xpath command to extract fields from XML. Based on the your needs you can extract individual field or as multi valued fields.