Splunk Enterprise

Why am I unable to ingest xml data into Splunk?

sagar_shubham23
Explorer

I am tring to ingest xml file data using below inputs.conf configuration.

I am unable to ingest the data. i am not getting any ERROR in internal logs as well.

Source Path is as follows: 

D:\ARDS\MASS\Data\ExecutionReport\ExecutionReport_Task[SendLabelNetisuq]_Job[5c522e65-a46f-4445-a9ca-3192e6c391b7]_20230614-182807-394995.xml

[monitor://D:\ARDS\MASS\Data\ExecutionReport\ExecutionReport_Task[SendLabelNetisuq]_Job*_*.xml]

disabled = false

sourcetype = abc:xyz:executionreport

index = log_abc

crcSalt=<SOURCE>

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Have you try to escape [] characters as those have special meaning in regex?
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...