Dashboards & Visualizations

XML Parsing issue in splunk and needs to correlate the events

amarababu_katar
Loves-to-Learn Everything

Hi Team,

Huge XML files are loading into Splunk and based on the xml we needs to fetch the number values and sum it display in splunk dashboard.
From the screen shot each line treated as one event in splunk and from those events i needs to extract name field and extracting number which is before the japan word(which is in light greeen color).
i'm not able to correlate noted screen shot, please help how to extract and correlate the events from the screen shot.

i'm attaching xml splunk event screen shot.alt text

Tags (3)
0 Karma

to4kawa
Ultra Champion

サニタイズしたログの提示をお願いします。

Please provide sanitized logs.

0 Karma
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...