If anyone is coming across this in 2022, you should know that there's a pretty easy workaround for this nowadays. The issue is with XML parsing, but Splunk allows you to output the results in JSON format with a simple change to your rest query. Instead of my query for lookup transforms: | rest /servicesNS/nobody/app/data/transforms/lookups splunk_server=local You just add the output_mode=json GET argument to it, like so: | rest /servicesNS/nobody/app/data/transforms/lookups output_mode=json splunk_server=local This resolved this issue for me immediately.
... View more