Here is what I have tried and it is not working:
Edit the local/inputs.conf file and add this:
[monitor:///directory/*.xml]
sourcetype = panorama:api:templates
index = qt_palo
crcSalt = Belton Palo-Templates
alwaysOpenFile = 1
disabled = false
[monitor:///directory/*.xml]
sourcetype = panorama:api:templates
index = qt_palo
crcSalt = Tulsa Palo-Templates
alwaysOpenFile = 1
disabled = false
[monitor:///directory/*.xml]
sourcetype = panorama:api:devicegroups
index = qt_palo
crcSalt = Belton Palo-Templates
alwaysOpenFile = 1
disabled = false
[monitor:///directory/*.xml]
sourcetype = panorama:api:devicegroups
index = qt_palo
crcSalt = Belton Palo-Device Groups
alwaysOpenFile = 1
disabled = false
Create a local/props.conf file and add this:
[panorama:api:templates]
EXTRACT-Status = (?i)<response status>(?P<Status>[^<]+)
EXTRACT-Name = (?i)<entry name>(?P<Name>[^<]+)
EXTRACT-TemplateStack = (?i)<template-stack>(?P<TemplateStack>[^<]+)
EXTRACT-EntryName = (?i)<entry name>(?P<EntryName>[^<]+)
EXTRACT-Serial = (?i)<serial>(?P<Serial>[^<]+)
EXTRACT-Connected = (?i)<connected>(?P<Connected>[^<]+)
EXTRACT-UnsupportedVersion = (?i)<unsupported-version>(?P<UnsupportedVersion>[^<]+)
EXTRACT-LastCommitAllStateTPL = (?i)<last-commit-all-state-tpl>(?P<LastCommitAllStateTPL>[^<]+)
EXTRACT-LastValidateAllStateTPL= (?i)<last-validate-all-state-tpl>(?P<LastValidateAllStateTPL>[^<]+)
EXTRACT-Connected = (?i)<XMLtagInRawEvent1>(?P<YourXMLExtractionName1>[^<]+)
EXTRACT-Connected = (?i)<XMLtagInRawEvent1>(?P<YourXMLExtractionName1>[^<]+)
EXTRACT-Connected = (?i)<XMLtagInRawEvent1>(?P<YourXMLExtractionName1>[^<]+)
EXTRACT-Connected = (?i)<XMLtagInRawEvent1>(?P<YourXMLExtractionName1>[^<]+)
EXTRACT-Connected = (?i)<XMLtagInRawEvent1>(?P<YourXMLExtractionName1>[^<]+)
EXTRACT-Connected = (?i)<XMLtagInRawEvent1>(?P<YourXMLExtractionName1>[^<]+)
EXTRACT-Connected = (?i)<XMLtagInRawEvent1>(?P<YourXMLExtractionName1>[^<]+)
Are you having issues parsing the XML file? If so you need to include KV_MODE =1
in your props.conf
on the indexer(s)