All of our data is in XML format that is being indexed. I've been able to pull out a lot of extractions for single value attributes or element values.
However I've yet to be able to figure out how to deal with multivalue xpaths. I've tried using xmlkv but there is little to no documentation in the Splunk documentation and answers.splunk.com.
IE:
<a>1</a><a>2</a><a>3</a>
I want a field or fields pulled out with a certain name for the values 1,2 and 3. xmlkv doesn't seem to do anything. How can I get the values 1,2 and 3 pulled out into a field?
... View more