Hey Friends
I'm having a lot of issues importing an XML file to my Splunk Enterprise. Actually, I'm a new user to Splunk and still trying without success inthis xml file.
Googling around, I figured out that the right file to configuring this parsing should be props.conf, but I already tried to make some changes and configurations inside props.conf, but didn't see a way to do it right.
Indeed, this file is a result from a NetScan and I'm not getting how to configure this property.
Could you guys give me a little help?
Below you can see a sample of file that I'm trying to parse. Pay attention that when this scan found additional information regarding share to specific device, this also insert as a parameter for folder, and, unfortunately we cannot change the way that this report is issued.
Network Scanner 2016-02-01T13:14:51.570-02:00 10.77.4.57 000000000000 1 10.77.4.58 000000000000 0 10.77.4.61 MPC3001 printer IPC$ ipc RNP002673377C09 002673377C09 8 10.77.4.90 000000000000 0 10.77.4.91 000000000000 2 10.77.4.92 000000000000 0 10.77.4.93 000000000000 1 10.77.4.94 000000000000 0 10.77.4.95 000000000000 5
Could you guys give-me a little help how can I Parse that?
↧