When I conduct a generic search on one of our Splunk sources, I am looking for relevant data which will assist with categorizing and analyzing the data.
I noticed that this particular batch of data did not have too many unique identifying fields which were useful for my analysis (eg, customer id, etc).
However, when I took a closer look at some of the results XML data, I could see that there was indeed some relevant identifying data which was contained within tags. For example, for the purpose of this question lets say;
< customer-id >0100000< /customer-id >
(Without the spaces)
I am wondering why this data does not display as a field which I can manipulate/sort by/etc within the search results.
Is this not a valid XML tag which is therefore a field?