Hi
Which is best format to index for the splunk indexer XML or JSON... what is recommendation from SPlunk like which format is efficient.
Thanks
Splunk recommended log format is key-value paired, but to decide between JSON or XML, JSON should be a better selection.
See section 'Use developer-friendly formats' in the below link.
http://dev.splunk.com/view/logging-best-practices/SP-CAAADP6