Splunk Search

Creating operacional intelligence in xml file.

dfigurello
Communicator

Hey guys,

I am writing a script to colect data from social media and generate a XML file. I would like to index theses data into Splunk for operacional intelligence. The section of file is below:

  <posts>
  <post>
    <id>112820708797552_683839761695641</id>
    <created_time>2014-05-29T13:59:42+0000</created_time>
    <link>https://www.facebook.com/photo.php?fbid=683839435029007&amp;set=a.128321133914176.33759.112820708797552&amp;type=1&amp;relevant_count=1</link>
    <updated_time>2014-05-29T17:17:41+0000</updated_time>
    <message>#EuSouGV</message>
    <picture>https://fbcdn-photos-a-a.akamaihd.net/hphotos-ak-xfa1/t1.0-0/10169278_683839435029007_2198735282545424462_s.jpg</picture>
    <share_count>453</share_count>
    <likes>
      <like>
        <id>10201494776325765</id>
        <name>Alan Pereira</name>
      </like>
      <like>
        <id>306388969523820</id>
        <name>Brenda Caroline Da Costa Araujo</name>
      </like>
      <like>
        <id>545806832196917</id>
        <name>Nilson Henrique Dias</name>
      </like>
      <like>
        <id>248400922029354</id>
        <name>Priscila Vieira Oliveira</name>
      </like>
    <comments>
      <comment>
        <id>683839435029007_683840308362253</id>
        <message>Quebra de paradigmas! hahaha</message>
        <created_time>2014-05-29T14:00:22+0000</created_time>
        <like_count>33</like_count>
        <from>
          <id>714740528584304</id>
          <name>Gabriel Vinicius Cardoso Rodrigues</name>
        </from>
      </comment>
      <comment>
        <id>683839435029007_683841071695510</id>
        <message>Isso ai, coisas inúteis que a sociedade coloca em nosso subconsciente para nos limitar, podemos muito mais!</message>
        <created_time>2014-05-29T14:02:32+0000</created_time>
        <like_count>24</like_count>
        <from>
          <id>631984613554612</id>
          <name>Alberto Gomes</name>
        </from>
      </comment>
      <comment>
        <id>683839435029007_683846898361594</id>
        <message>De fato! Quanto mais conseguirmos colocar na mão, mas bem sucedido seremos. Obrigado pela frase que como o Gabriel disse, quebra paradigmas.</message>
        <created_time>2014-05-29T14:18:23+0000</created_time>
        <like_count>4</like_count>
        <from>
          <id>798637020148028</id>
          <name>Kevin Couto</name>
        </from>
      </comment>
      <comment>
        <id>683839435029007_683845468361737</id>
        <message></message>
        <created_time>2014-05-29T14:14:19+0000</created_time>
        <like_count>4</like_count>
        <from>
          <id>689198677800564</id>
          <name>Daniel De Jesus Ribeiro</name>
        </from>
      </comment>
      <comment>
        <id>683839435029007_683904491689168</id>
        <message>Mais vale um pássaro na mão do que dois voando = pensamento de perdedor. O país não vai pra frente por esse tipo de pensamento, conformismo e comodidade, a maioria das pessoas adora isso, por esse motivo poucos tem um lugar ao sol.</message>
        <created_time>2014-05-29T16:23:57+0000</created_time>
        <like_count>3</like_count>
        <from>
          <id>579827312133498</id>
          <name>Luana Minatti</name>
        </from>
(...)

</comment>
     </post>
</posts>

Please, I need a help creating props.conf file. I don't have much experience with regex. My goal is to create a social media analytics.

Thank you very much,

0 Karma

somesoni2
Revered Legend

This can give a start.

Props.conf

[facebook]
BREAK_ONLY_BEFORE = \<posts\>
KV_MODE = xml
NO_BINARY_CHECK = 1
SHOULD_LINEMERGE = true
pulldown_type = 1
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...