Dashboards & Visualizations

XML Parsing issue in splunk and needs to correlate the events

amarababu_katar
Loves-to-Learn Everything

Hi Team,

Huge XML files are loading into Splunk and based on the xml we needs to fetch the number values and sum it display in splunk dashboard.
From the screen shot each line treated as one event in splunk and from those events i needs to extract name field and extracting number which is before the japan word(which is in light greeen color).
i'm not able to correlate noted screen shot, please help how to extract and correlate the events from the screen shot.

i'm attaching xml splunk event screen shot.alt text

Tags (3)
0 Karma

to4kawa
Ultra Champion

サニタイズしたログの提示をお願いします。

Please provide sanitized logs.

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...