Hi All,
I have log file which has XML content in one of the fields and I need to extract its key value pairs. Can you please help me on this?
Please provide me any examples.
Thanks
Sathish Rangan
Hi, you can use the spath command for that:
http://docs.splunk.com/Documentation/Splunk/6.3.2/SearchReference/Spath
See the examples there
Hi, you can use the spath command for that:
http://docs.splunk.com/Documentation/Splunk/6.3.2/SearchReference/Spath
See the examples there
Thank you javiergn. it is great help..
Is that can be done in the index time using props/trans conifg instead of search query ?
Yes, you can use KV_MODE = xml in your props.conf
See this
Some other related answers:
https://answers.splunk.com/answers/2889/automatically-extract-xml-key-value-pairs.html
https://answers.splunk.com/answers/29212/extracting-xml-log-files.html
Not sure what you mean by that. Multiple fields as in different field names or multiple values per field?
Can you give me an example? If you post your XML and the result you are expecting it might be easier.
Short answer anyway: yes you can extract multiple field names from your XML and also multivalue fields (see this)
can we extract multiple fileds ??