I'm looking for a data sourcetype to use with monitoring an endpoint using XML parser. What would be the correct datasource type to configure the data input in splunk as XML instead of raw?
Raw Output:
POST syslog.name.com HTTP/1.1 Host: 10.10.10.10 User-Agent: CyberData/1.0.0 Content-Length: 195 Content-Type: application/x-www-form-urlencoded %3c%3fxml+version%3d%221.0%22+encoding%3d%22ISO-8859-1%22%3f%3e%0a%3ccyberdata+NAME%3d%27Front+Door+Intercom%27+MAC%3d%270020f7020ce7%27%3e%0a%3cevent%3ePOWERON%3c%2fevent%3e%0a%3c%2fcyberdata%3e
If you haven't found the answer already, check out these two other posts
https://answers.splunk.com/answers/2141/xml-log-source-type.html
https://answers.splunk.com/answers/187195/how-to-add-and-parse-xml-data-in-splunk.html