We are trying to make a REST input and the result is XML data but it has no schema. The Source we are using is the Palo Alto, specifically Panorama, not the firewalls directly. Can someone help me create an XML schema??? (I have been stuck on this for a while!) Is there a way to manually build a schema in splunk for this input?
Well, without a sample log it won't be easy to help you.
Did you try with :
KVMODE = xml
Actually, KV_MODE = xml
.