Getting Data In
Highlighted

XML parsing with condition

Engager

Hi

I am novice to splunk and need help in writing a splunk query in order to find Order ID (ORD********)


Sample XML


0 Karma
Highlighted

Re: XML parsing with condition

Motivator

run in bar search the following search:
index=yourindexname

or
index=yourindexname source=yoursourcename sourcetype=yoursourcetypename

index=yourindexname source=yoursourcename sourcetype=yoursourcetypename|....yourcondictionssearch
exple:
index=youindex host=youhost "Error" | chart count sparkline(count, 1h) as trend by host | sort -count

0 Karma
Highlighted

Re: XML parsing with condition

SplunkTrust
SplunkTrust

Is this even related to the question?

0 Karma
Highlighted

Re: XML parsing with condition

SplunkTrust
SplunkTrust

I can't see your sample data.

0 Karma