Splunk Search

How do you extract the following XML fields?

Rajkumarkbm2
Explorer

Hello,

I need to extract the fields from the below xml. Please help me on this. I want to extract fields from event and then from Status.

alt text

0 Karma

JDukeSplunk
Builder
0 Karma

Rajkumarkbm2
Explorer

Yes tried but not able to split properly

0 Karma

Sukisen1981
Champion

Hi,
What happens when you sort of just append |xmlkv to your index? I know you said that it does not work, but what do you see? Are no fields getting extracted or the fields you want are not getting auto extracted in the left hand side?
The snapshot you have given , is that a raw event as in looks in your splunk xml index right now? If yes, is there any harm in using regex to extract the fields you want from the raw events?

Regards,
Suki

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...