Reporting

Data Model - How to easily add XML elements

czzpl9
New Member

Have recently installed the new Splunk 6 and started the process of building Data models. Most of my data sources tend to be application based logs with very mixed formats and it doesn't make sense to specify the entire file as XML. As a result, when building a targeted search/dashboard I will pipe "|" my search to xmlkv to extract the input request portion.

With the new Data Model, it is easy enough to add children that narrow the search result to just the lines that contain XML data, but I'm not seeing a way to easily add all XML attributes (short of 1 by 1 single extractions)

Am I overlooking something?

Tags (2)
0 Karma
1 Solution

kpdonahoe31768
Explorer

I've been adding eval expression attributes using the spath(_raw,Parent.Child{@attribute}) method to get at all my xml attribute=value pairs.

View solution in original post

0 Karma

kpdonahoe31768
Explorer

I've been adding eval expression attributes using the spath(_raw,Parent.Child{@attribute}) method to get at all my xml attribute=value pairs.

0 Karma

splunk_worker
Path Finder

Hi

I'm also facing the same problem. Where to add spath(_raw,Parent.Child{@attribute}) in Data Modeling step?

This is my query and I want to add it to Data Model. Can you please help me with steps?

index=abc | rex "(?{[^}]+})" | mvexpand json_field | spath input=json_field

  1. created root event with index=abc
  2. added a regular express for json_field.

What is the next step for spath? If would be great if you give the steps.

Thanks in advance.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...