I'm looking for a data sourcetype to use with monitoring an endpoint using XML parser. What would be the correct datasource type to configure the data input in splunk as XML instead of raw?
Raw Output:
POST syslog.name.com HTTP/1.1 Host: 10.10.10.10 User-Agent: CyberData/1.0.0 Content-Length: 195 Content-Type: application/x-www-form-urlencoded %3c%3fxml+version%3d%221.0%22+encoding%3d%22ISO-8859-1%22%3f%3e%0a%3ccyberdata+NAME%3d%27Front+Door+Intercom%27+MAC%3d%270020f7020ce7%27%3e%0a%3cevent%3ePOWERON%3c%2fevent%3e%0a%3c%2fcyberdata%3e
... View more