Dashboards & Visualizations

How do I extract field values from XML logs?

aruotolo
New Member

Hi,

I have log files containing text and XML. I need to extract all fields from the XML rows.

alt text

I tried using

Props.conf:

TRUNCATE = 0
NO_BINARY_CHECK = 1
pulldown_type = 1
KV_MODE = xml
TRANSFORMS = itepm339-xml

And transforms.conf

REGEX = \<(\w+[^\n\/\>]+)\/?\>([^\<\n][^\<]*)\<
FORMAT = $1::$2

It works, but extracts only the first couple field-value from XML:

alt text

Please can you help me to understand what i am missing?

Tags (2)
0 Karma

nswondem
Path Finder

Hello aruotolo,

Please refer to a previously answered question at https://answers.splunk.com/answers/587570/index-time-field-extraction-for-xml-data-1.html

Thanks
nswondem

0 Karma

aruotolo
New Member

Hi @Nswondem

but the page of your link doesn't exist error 404.

Alfredo

0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @nswondem,

there was just a typo in that link. I've removed it, and now you should be able to click it. Hopefully it helps you with your query! Let us know.

Thanks for posting!

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...