Hi,
I have a log file named Audit.Log and has content something like below.
< AuditLog >
< Comp name="samsung"/ >
< Actor name="actor"/ >
< User name="reguser"/ >
< LogComments> This is a test message< / LogComments >
< TimeStamp="455454545xxx"/ >
< / AuditLog >
I would want to retrieve the data as
This is a test message , reguser in the form of a table.
could someone throw some light onto the same, I am not much familiar with the splunk commands.
Try | xmlkv in your search. It will extract all tags as fields with corresponding values on the left. Then you can format your query to show it as table.
Reference : http://docs.splunk.com/Documentation/Splunk/6.2.3/SearchReference/Xmlkv