Dashboards & Visualizations

XML Parsing issue in splunk and needs to correlate the events

amarababu_katar
Loves-to-Learn Everything

Hi Team,

Huge XML files are loading into Splunk and based on the xml we needs to fetch the number values and sum it display in splunk dashboard.
From the screen shot each line treated as one event in splunk and from those events i needs to extract name field and extracting number which is before the japan word(which is in light greeen color).
i'm not able to correlate noted screen shot, please help how to extract and correlate the events from the screen shot.

i'm attaching xml splunk event screen shot.alt text

Tags (3)
0 Karma

to4kawa
Ultra Champion

サニタイズしたログの提示をお願いします。

Please provide sanitized logs.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...