Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

xml field extraction

$
0
0
I have one xml file I want to extract (at search time) the fields/values IN BETWEEN and and throw away any of the lines before the very first and after the very last . (In XML, the fields/values are located on each line in the form value) 4. Use the date in the ActionDate field and the time in the ActionTime field as the timestamp.-423423445345345.10742916222947Inteccccn20Iwildwood2013-04-2400:07:000-80.23429525620114,24.08680387475695local below is my props.conf and transforms.conf props.conf [dreamcrusher] BREAK_ONLY_BEFORE = DATETIME_CONFIG = NO_BINARY_CHECK = true TIME_FORMAT = TIME_PREFIX = category = Custom disabled = false pulldown_type = true PREAMBLE_REGEX = ^<\S+.* REPORT-dream = dream transforms.conf [dream] REGEX = ^\<(.*?)\>(\S+)\< FORMAT = $1::$2 ====== when i check the events there are no search time extraction

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>