Hi! Just for the record, we've made progress, whereby we've changed the value of 'LINE_BREAKER = ' from the default '([\r\n]+)' to '<record>' in the $SPLUNK_HOME/etc/system/local/props.conf file, because the indexer could not seem to parse the incoming .xml data, as configured in that format on the Forecepoint SMC. The above was determined from this article: https://community.splunk.com/t5/Dashboards-Visualizations/How-to-do-event-break-for-XML-file-like-this/m-p/383203 Now we can see event data in the Splunk Ent. Web UI > Apps > Forcepoint, which we couldn't before, but in the Search & Reporting app the event data still cannot seem to be broken into columns if changed to Table view - not sure if that's how data is supposed to be displayed in the first place... Thanks for your input PickleRick! Much appreciated! Regards, Lubo
... View more