Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to extract XML fields combining event?

$
0
0
- -2013-02-09 20:40:102016-03-23 18:20:06MediumBuesiness007-123More store -Reference1Reference2ReferenceReferenceSummary of Customerpurchase anaysis 3 similer as above i modified props.config as following [XML] DATETIME_CONFIG = CURRENT KV_MODE = xml LINE_BREAKER = () MUST_BREAK_AFTER = \ NO_BINARY_CHECK = 1 SHOULD_LINEMERGE = false TRUNCATE = 0 pulldown_type = 1 probleam is splunk creat 3 events for each customer inforamtion event one event two 2013-02-09 20:40:10 event 3 2016-03-23 18:20:06 Medium Buesiness 007-123 - Reference1 Reference2 Reference Reference Summary of Customer purchase anaysis 3 i want one customers info in single event

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>