I have a XML file with multi values on a specific tag (below).
I need to extract the attributes (NAME and CLASSORIGIN) and the VALUE , ignoring the rows without the tag VALUE.
I loaded the file as a XML and I was able to convert this to a multi-line result but now I need to extract the fields. Any ideas?
Solved it.
index=msperf sourcetype="perfmon_processor_xml" 
| xpath outfield=Architecture "//COMMAND/RESULTS/CIM/INSTANCE/PROPERTY" 
| where Architecture != "Null" 
| table Architecture 
| mvexpand Architecture 
| rex field=Architecture "^[^=\n]=\"(?P\w+)[^=\n]=\"(?P[^\"]+)[^<\n]*<\w+>(?P\w+)"
Solved it.
index=msperf sourcetype="perfmon_processor_xml" 
| xpath outfield=Architecture "//COMMAND/RESULTS/CIM/INSTANCE/PROPERTY" 
| where Architecture != "Null" 
| table Architecture 
| mvexpand Architecture 
| rex field=Architecture "^[^=\n]=\"(?P\w+)[^=\n]=\"(?P[^\"]+)[^<\n]*<\w+>(?P\w+)"
Did you try using spath. Append |spath at the end of your search and see if it works for you.
Yes, I did for some reason the fields could not be extracted.
appending only | spath doesn't show me nothing different. When I try 
index=msperf sourcetype="perfmon_processor_xml" 
| xpath outfield=Architecture "//COMMAND/RESULTS/CIM/INSTANCE/PROPERTY" 
| mvexpand Architecture 
| table Architecture 
| where Architecture != "Null" 
| spath 
| rename PROPERTY.VALUE as Value 
| rename PROPERTY.{@NAME} as Name 
| table Name Value
the search results nothing. Maybe I'm missing something on the rename command.
Give it a shot index=msperf sourcetype="perfmon_processor_xml" |spath
index=msperf sourcetype="perfmon_processor_xml" 
| spath 
| rename COMMAND.RESULTS.CIM.INSTANCE.PROPERTY.VALUE as Value 
| rename COMMAND.RESULTS.CIM.INSTANCE.PROPERTY{@NAME} as Name 
| table Name Value
Returned a single row with 2 multi-line fields, but the problem is: some rows doesn't have the VALUE tag and the columns have a different number of values.
