Hello,
When i indexed a XML file in local machine (Splunk version 5) with option CHECK_MODE=xml for sourtype "test_XML" , i saw clearly the fields that Splunk extracted, in the left hand, have the formats such as: table{@id} , table.content{@text} ...
But if i use splunk Universal Forwarder to forward that file to indexer (both have version 4.3.4), with CHECK_MODE=xml for that sourcetype, what i got in the left hand were : id, text... and i couldn't get any new field even using spath too. Can you tell me what is the problem ?
The file is just one-lien long xml format.
i don't know whether it's totally correct, when i upgrade all Splunk instances in my system \ to Version 5, all would be solved.
i don't know whether it's totally correct, when i upgrade all Splunk instances in my system \ to Version 5, all would be solved.