Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Is there a way to turn XML attribute/values into Splunk extracted fields?

$
0
0
Hi guys; Tricky problem here. I have XML coming in via REST that contains performance data for an appliance. I have to find a way to take the data and build some nice dashboards off of it. Here is an example of the data: 00x10000d0.0070827796393085991.2112084982652817E92.0322754560000002E91.672179712E100.0144.388882056081680.067.09483369780527000.00.010.0007739.4969587341774774.594256242269351.0999153065213981.099915306521398403.4689328921673516160.155668013564258.380104731935660.279978353446772439.4969587341774774.594256242269350.00.07.918264320000222E8 Sorry for the lack of pretty-print, but i wanted to represent the data as it is in my events. Anyway, I have a lookup table that correlates the attribute id's to human readable values. Is there a way, that I can build some logic that will take each attribute id, grab the human readable value from lookup, and then build a field with its corresponding attribute value? spath already gives me fields like: attribute attribute{@id}

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>