Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

XML parsing with multiple paths or depths?

$
0
0
Hi, We are evaluating Checkmarx tool that export data in XML. It has multiple paths or depths, and essecial information is presented only on "parent" path. I can parse via props.conf only on path at a time, and have to choose the best approach to ingest all data. Here is my current props.conf [risk_checkmarx] KV_MODE = xml BREAK_ONLY_BEFORE = \ NO_BINARY_CHECK = true TRUNCATE = 0 category = Application description = Checkmarx disabled = false pulldown_type = true MAX_EVENTS = 99999 What we need: - Parse XML to "duplicate each line" in a depth. (Ex: "Query\Result\Path") - Props and Transforms (index time) What we tried: - props = kv_mode - transforms = report / regex - search = xpath... Here is a xml sample C:\CxAuditSrc\cacti-0.8.8h\include\csrf\csrf-magic.php2610350524_x0024_NS_csrf_magic_1465816182._x0024_Cls_csrf_magic_1465816182.csrf5C:\CxAuditSrc\cacti-0.8.8h\include\csrf\csrf-magic.php3310350530_x0024_NS_csrf_magic_1465816182._x0024_Cls_csrf_magic_1465816182.csrf5C:\CxAuditSrc\cacti-0.8.8h\include\csrf\csrf-magic.php14453506706C:\CxAuditSrc\cacti-0.8.8h\lib\adodb\adodb-error.inc.php9453294596

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>