AnsweredAssumed Answered

How to parse an "XML" kind of format log into SA?

Question asked by Erika Szabo on May 26, 2017
Latest reply on May 31, 2017 by Erika Szabo

Hi All! 

I should create a new custom netwitness log parsers for a database from syslog, but the format is like XML, so the esi tool can not cope with the <> characters. 

Log Sample: 

May 25 07:21:32 db db: <ROW><DB_NAME>db045</DB_NAME><ACTION_NAME>LOGOFF</ACTION_NAME><RETURN_CODE>0</RETURN_CODE>

May 25 07:21:32 db db: <ROW><DB_NAME>db045</DB_NAME><ACTION_NAME>LOGON</ACTION_NAME><RETURN_CODE>0</RETURN_CODE>

I set to bold the variables we need to parse. The other part of the log is static. Is there a way to do this? 

Thank You, Erika

Outcomes