Getting Data In

We are trying to make a REST input and the result is XML data but it has no schema.

rshoun
Explorer

We are trying to make a REST input and the result is XML data but it has no schema. The Source we are using is the Palo Alto, specifically Panorama, not the firewalls directly. Can someone help me create an XML schema??? (I have been stuck on this for a while!) Is there a way to manually build a schema in splunk for this input?

Tags (1)

3no
Communicator

Well, without a sample log it won't be easy to help you.

Did you try with :

KVMODE = xml 

woodcock
Esteemed Legend

Actually, KV_MODE = xml.

0 Karma
Get Updates on the Splunk Community!

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...