Hello,
I need to extract the fields from the below xml. Please help me on this. I want to extract fields from event and then from Status.
Have you tried |spath or |xmlkv?
http://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Xmlkv
Yes tried but not able to split properly
Hi,
What happens when you sort of just append |xmlkv to your index? I know you said that it does not work, but what do you see? Are no fields getting extracted or the fields you want are not getting auto extracted in the left hand side?
The snapshot you have given , is that a raw event as in looks in your splunk xml index right now? If yes, is there any harm in using regex to extract the fields you want from the raw events?
Regards,
Suki