Hi @PierrAlezOCD It looks like the data is being received from BeyondTrust by the API because its referencing a specific line that is failing the xml function which makes me wonder if something is incorrect or changed in the events received from BeyondTrust which the app cannot handle. Are you using the latest version of the app from Splunkbase? You may be able to speak to BeyondTrust directly through your support channels with them as they state in the docs that they do support the Splunk app (https://docs.beyondtrust.com/rs/docs/splunk) 🌟 Did this answer help you? If so, please consider: Adding karma to show it was useful Marking it as the solution if it resolved your issue Commenting if you need any clarification Your feedback encourages the volunteers in this community to continue contributing
... View more