Splunk Search

Using if condition in input and path fields of spath

sasireka
Loves-to-Learn Lots

I have an xml file and using spath for it.

My xml is having a tag like:
<messages>
<name>test1</name>
<message-a>
<cust-id>cust-1</cust-id>
<part-a>name-1</part-a>
<part-b>name-2</part-b>
</message-a>
<message-b>
<cust-id>cust-2</cust-id>
<part-a>name-1</part-a>
<part-b>name-2</part-b>
</message-b>
<messages>

I want to use a if condition in both input and path fields of spath

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

On the face of it, I don't think what you are asking for is possible. Perhaps if you could explain what it is you are trying to achieve e.g. what are you trying to extract from the XML, someone may be able to assist you more readily.

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...