My XML file looks like ( I have added spaces for formatting )
< contentOwner>
< gln>113456789< /gln>
< contentOwner>
< gln>1423456791< /gln>
< /contentOwner>
< contentOwner>
< gln>193456795
< /contentOwner>
and I want to extract a single multi event fields GLN=113456789,1423456791,193456795
How can I do that?
Hi mzorzi
I cannot test it, but I would try to use spath
with your XML like this
... | spath output=gln path=contentOwner.gln
see spath
examples here http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Spath#Examples
cheers, MuS