Hello everyone
I have xml formalt like:
<CxXMLResults>
<Query>
<Result>
</Result>
</Query>
</CxXMLResults>
So my fields looks like that in Splunk:
So I select Stored_XSS vulnerability in search for example CxXMLResults.Query{@name}=Stored_XSS and I want to count how many are there Stored_XSS with CxXMLResults.Query.Result{@NodeId}.
And I am doing searching like:
CxXMLResults.Query{@name}=* | stats count(CxXMLResults.Query.Result{@NodeId}) by CxXMLResults.Query{@name}
The result is all the same 😞 because these are in a single event. How can I select these with parent, child relations?