Getting Data In

reading an xml file in splunk

a212830
Champion

Hi,

I have an xml file that I am being asked to import into Splunk. How would I configure this?

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

As any other file - figure out where event breaks and time stamps are, estimate maximum line and byte count per event, and configure that in props.conf - done.

If you need specific help with your format you'll have to post some samples along with what you've tried already.

a212830
Champion

OK. Thanks.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

There's the KV_MODE=xml switch in props.conf, but that's for search time field extraction. First you need to get index-time settings right, and those can differ between XML sources depending on the specific source.

0 Karma

a212830
Champion

OK. I thought Splunk automatically handled xml with some config settings?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...