Splunk Search

search fails in xml file

DTERM
Contributor

The following search works fine in the Splunk search:

index=mydata | rex "\s+IP\s+(?\d+.\d+.\d+.\d+).(?\S+)\s+>\s+(?\d+.\d+.\d+.\d+).(?[a-z0-9]+):\s+" | top src_ip

When I take that same search and place it in an xml file like:

  <searchTemplate>

index=dns | rex "\s+IP\s+(?\d+.\d+.\d+.\d+).(?\S+)\s+>\s+(?\d+.\d+.\d+.\d+).(?[a-z0-9]+):\s+" | top src_ip

It fails. (That search in the XML starts and ends with the searchTemplate tags although I don't see those in this post, though they are there.) I get the following error when trying to start Splunk:

Checking configuration... Error while parsing '/opt/splunk/etc/apps/myApp/default/data/ui/views/source.xml':

mismatched tag: line 6, column 4

I don't see the mismatched tag. What is the problem with the XML?

Thanks.

Tags (1)
0 Karma
1 Solution

bmacias84
Champion

The problem with your search is the ">" and "<". The angel brackets are treated as part of XML tags. Replace those with the HTML entities & lt; and & gt; . Hope that fixes your problem.

View solution in original post

bmacias84
Champion

The problem with your search is the ">" and "<". The angel brackets are treated as part of XML tags. Replace those with the HTML entities & lt; and & gt; . Hope that fixes your problem.

DTERM
Contributor

Based on this response, I've created the following search:

index=data | rex "\s+IP\s+(?<src_ip> \d+.\d+.\d+.\d+).(?<src_port>\S+)\s+>\s+(?<dest_ip>\d+.\d+.\d+.\d+).(?<dest_port>[a-z0-9]+):\s+" | top src_ip

This still fails in the XML file. Is there anything within Splunk that helps resolve such regular expressions? Why does this not work? What is incorrect?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...