<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Parsing Splunk log in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592579#M76525</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244600"&gt;@hungln9&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it mainly depends on how many instances you have to display.&lt;/P&gt;&lt;P&gt;There a limit in chart but it's very high (hundreds of bars), the main limit is the readability of your chart.&lt;/P&gt;&lt;P&gt;maybe you could create more panels displaying a group of instances.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Apr 2022 06:21:50 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-04-06T06:21:50Z</dc:date>
    <item>
      <title>How to get max memory used value in each message and create time chart to show max memory used value and average?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592379#M76509</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Teams,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am newbie to splunk, I have log message like this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE width="791px"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="98px"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;4/5/22&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;6:03:22.697 PM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="692px"&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN class=""&gt;2022-04-05T10:03:22.697Z&lt;/SPAN&gt; &lt;SPAN class=""&gt;802cf235-b8d6-454e-bb1a-25d16f6b5f21&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;802cf235-b8d6-454e-bb1a-25d16f6b5f21&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFO:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Insert&lt;/SPAN&gt; &lt;SPAN class=""&gt;batch&lt;/SPAN&gt; &lt;SPAN class=""&gt;0/6&lt;/SPAN&gt; &lt;SPAN class=""&gt;END&lt;/SPAN&gt; &lt;SPAN class=""&gt;RequestId:&lt;/SPAN&gt; &lt;SPAN class=""&gt;802cf235-b8d6-454e-bb1a-25d16f6b5f21&lt;/SPAN&gt; &lt;SPAN class=""&gt;REPORT&lt;/SPAN&gt; &lt;SPAN class=""&gt;RequestId:&lt;/SPAN&gt; &lt;SPAN class=""&gt;802cf235-b8d6-454e-bb1a-25d16f6b5f21&lt;/SPAN&gt; &lt;SPAN class=""&gt;Duration:&lt;/SPAN&gt; &lt;SPAN class=""&gt;601.44&lt;/SPAN&gt; &lt;SPAN class=""&gt;ms&lt;/SPAN&gt; &lt;SPAN class=""&gt;Billed&lt;/SPAN&gt; &lt;SPAN class=""&gt;Duration:&lt;/SPAN&gt; &lt;SPAN class=""&gt;602&lt;/SPAN&gt; &lt;SPAN class=""&gt;ms&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Memory&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;Size:&lt;/SPAN&gt; &lt;SPAN class=""&gt;1024&lt;/SPAN&gt; &lt;SPAN class=""&gt;MB&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class=""&gt;Max&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Memory&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;Used:&lt;/SPAN&gt; &lt;SPAN class=""&gt;97&lt;/SPAN&gt; &lt;SPAN class=""&gt;MB&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to get&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class=""&gt;Max&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Memory&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;Used&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;value in each message and create time chart to show&amp;nbsp;&lt;STRONG&gt;Max &lt;SPAN class=""&gt;Memory&lt;/SPAN&gt; Used&amp;nbsp;&lt;/STRONG&gt;value and the &lt;STRONG&gt;Max &lt;SPAN class=""&gt;Memory&lt;/SPAN&gt; Used&amp;nbsp;&lt;/STRONG&gt;average value. Can anyone help me in this!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 14:54:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592379#M76509</guid>
      <dc:creator>hungln9</dc:creator>
      <dc:date>2022-04-13T14:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592382#M76510</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244600"&gt;@hungln9&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you're sure that the maxmemory is always expressed in MB, you could run something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=your_index
| rex "Max Memory Used: (?&amp;lt;max_memory_used&amp;gt;\d+)"
| timechart max(max_memory_used) AS max_memory_used&lt;/LI-CODE&gt;&lt;P&gt;if instead you could also have GB, you should modify&amp;nbsp;a little the search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=your_index
| rex "Max Memory Used: (?&amp;lt;max_memory_used&amp;gt;\d+)\s+(?&amp;lt;mem_unit&amp;gt;\w+)"
| eval max_memory_used=if(mem_unit="GB",max_memory_used*1024,max_memory_used)
| timechart max(max_memory_used) AS max_memory_used&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 10:22:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592382#M76510</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-05T10:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592393#M76511</link>
      <description>&lt;P&gt;Many thanks&amp;nbsp;&lt;SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That is exactly what I need.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can I ask you 1 more things?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I want to include the instances infomation to the chart, in this message is &amp;nbsp;&lt;STRONG&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;802cf235-b8d6-454e-bb1a-25d16f6b5f21,&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;can you guide me:&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE width="791px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="98px"&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;4/5/22&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;6:03:22.697 PM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="692px"&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;2022-04-05T10:03:22.697Z&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;802cf235-b8d6-454e-bb1a-25d16f6b5f21&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;802cf235-b8d6-454e-bb1a-25d16f6b5f21&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;INFO:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Insert&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;batch&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;0/6&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;END&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;RequestId:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;802cf235-b8d6-454e-bb1a-25d16f6b5f21&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;REPORT&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;RequestId:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;802cf235-b8d6-454e-bb1a-25d16f6b5f21&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Duration:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;601.44&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Billed&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Duration:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;602&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ms&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Memory&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Size:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;1024&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;MB&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Max&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Memory&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Used:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;97&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;MB&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 05 Apr 2022 11:04:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592393#M76511</guid>
      <dc:creator>hungln9</dc:creator>
      <dc:date>2022-04-05T11:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592415#M76512</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244600"&gt;@hungln9&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in general, you have to find a rule to apply the regex: if in your case you want the string after INFo, you could use a regex like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "INFO\s+(?&amp;lt;instance&amp;gt;[^ ]+)"&lt;/LI-CODE&gt;&lt;P&gt;Tell me if I can help you more, otherwise, please, accept my answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 12:05:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592415#M76512</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-05T12:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592430#M76513</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244600"&gt;@hungln9&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;iuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 13:36:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592430#M76513</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-05T13:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592557#M76524</link>
      <description>&lt;P&gt;Thanks for your support,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean that I have a lot of instances(instance1, instance2....), and I want to show all of them on only 1 time chart, can you tell me, how can I do that?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 03:34:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592557#M76524</guid>
      <dc:creator>hungln9</dc:creator>
      <dc:date>2022-04-06T03:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592579#M76525</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244600"&gt;@hungln9&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it mainly depends on how many instances you have to display.&lt;/P&gt;&lt;P&gt;There a limit in chart but it's very high (hundreds of bars), the main limit is the readability of your chart.&lt;/P&gt;&lt;P&gt;maybe you could create more panels displaying a group of instances.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 06:21:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592579#M76525</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-06T06:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592594#M76527</link>
      <description>&lt;P&gt;Many thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I want to create send email alert when "max memory used" is greater than 1024.&lt;/P&gt;&lt;P&gt;I'm trying to save search&amp;nbsp;results as alert, but can not find the way to set or define this condition.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hungln9_0-1649229629561.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18961iEE9B002B5C381277/image-size/medium?v=v2&amp;amp;px=400" role="button" title="hungln9_0-1649229629561.png" alt="hungln9_0-1649229629561.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Can you please guide me?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 07:21:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592594#M76527</guid>
      <dc:creator>hungln9</dc:creator>
      <dc:date>2022-04-06T07:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592598#M76528</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244600"&gt;@hungln9&lt;/a&gt;.,&lt;/P&gt;&lt;P&gt;put this condition at the end of your search and set your alert to trigger when results&amp;gt;0:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=your_index
| rex "INFO\s+(?&amp;lt;instance&amp;gt;[^ ]+)"
| timechart max(max_memory_used) AS max_memory_used
| where max_memory_used&amp;gt;1024&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 07:45:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592598#M76528</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-06T07:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592626#M76539</link>
      <description>&lt;P&gt;Thanks for your support&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to add condition, but seem it not work, even I tried with value=10&lt;/P&gt;&lt;P&gt;&lt;EM&gt;index=my_index*&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| rex "Max Memory Used: (?&amp;lt;max_memory_used&amp;gt;\d+)"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| timechart max(max_memory_used) AS max_memory_used(MB)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| rex "INFO Done Lamda function\s+(?&amp;lt;D365&amp;gt;[^ ]+)"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;|where max_memory_used&amp;gt;10&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hungln9_0-1649236181382.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18965iB6891D5299625060/image-size/medium?v=v2&amp;amp;px=400" role="button" title="hungln9_0-1649236181382.png" alt="hungln9_0-1649236181382.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;While without condition, It worked&lt;/P&gt;&lt;P&gt;&lt;EM&gt;index=my_index*&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| rex "Max Memory Used: (?&amp;lt;max_memory_used&amp;gt;\d+)"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| timechart max(max_memory_used) AS max_memory_used(MB)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| rex "INFO Done Lamda function\s+(?&amp;lt;D365&amp;gt;[^ ]+)"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hungln9_1-1649236350108.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18966i823299E352746130/image-size/medium?v=v2&amp;amp;px=400" role="button" title="hungln9_1-1649236350108.png" alt="hungln9_1-1649236350108.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Can you pls take a look on this!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 09:13:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592626#M76539</guid>
      <dc:creator>hungln9</dc:creator>
      <dc:date>2022-04-06T09:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592631#M76540</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244600"&gt;@hungln9&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in the timechart, you renamed "max_memory_used(MB)" whilein the where condition you used "max_memory_used" that's different!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 09:35:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592631#M76540</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-06T09:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592801#M76548</link>
      <description>&lt;P&gt;Many thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem was&amp;nbsp;solved, no issue at all.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 03:05:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/592801#M76548</guid>
      <dc:creator>hungln9</dc:creator>
      <dc:date>2022-04-07T03:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593037#M76558</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Sorry for many question from me.&lt;/P&gt;&lt;P&gt;I have new trouble&lt;/P&gt;&lt;P&gt;I already created alert to send notify email to me once the max memory used is over. But I recevied a lot email notify in 1 minute, once alert was&amp;nbsp; triggered. I just want to trigger action send me 1 or some notify, Could you please guide me?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hungln9_0-1649389038166.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18998iE8AFB57DF663B2C9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="hungln9_0-1649389038166.png" alt="hungln9_0-1649389038166.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hungln9_1-1649389695429.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19001iD86963A4EF7D4284/image-size/medium?v=v2&amp;amp;px=400" role="button" title="hungln9_1-1649389695429.png" alt="hungln9_1-1649389695429.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 03:48:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593037#M76558</guid>
      <dc:creator>hungln9</dc:creator>
      <dc:date>2022-04-08T03:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593051#M76561</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244600"&gt;@hungln9&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;no problems for your questions!&lt;/P&gt;&lt;P&gt;Anyway, in this case you have to configure throttle in your alert, the period, after a triggering that the alert doesn't run.&lt;/P&gt;&lt;P&gt;You can find it in the Alert definition.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 06:18:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593051#M76561</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-08T06:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593559#M76588</link>
      <description>&lt;P&gt;Many thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is thing, what I need&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 06:26:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593559#M76588</guid>
      <dc:creator>hungln9</dc:creator>
      <dc:date>2022-04-13T06:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593563#M76589</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244600"&gt;@hungln9&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you're always welcome.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 07:25:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593563#M76589</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-13T07:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593572#M76590</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I have many sources in search result, can you guide me how can I group some resource into 1 chart?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;index=my_index* &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| rex "Max Memory Used: (?&amp;lt;max_memory_used&amp;gt;\d+)"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| timechart max(max_memory_used) AS max_memory_used by source&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hungln9_0-1649841124208.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19050i59A0279332005EB9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="hungln9_0-1649841124208.png" alt="hungln9_0-1649841124208.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I tried to group with this query, but seem it's incorrect:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;index=my_index* (source=source1 or source=2)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| rex "Max Memory Used: (?&amp;lt;max_memory_used&amp;gt;\d+)"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;| timechart max(max_memory_used) AS max_memory_used by source&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 09:14:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593572#M76590</guid>
      <dc:creator>hungln9</dc:creator>
      <dc:date>2022-04-13T09:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593574#M76591</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244600"&gt;@hungln9&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it's always better to ask a new question to the Community, so more people can help you better and quicker!&lt;/P&gt;&lt;P&gt;Anyway, using the second search, you use the same grouping options than the first but you filter your results&amp;nbsp; (in teh main search) taking only events from two sources.&lt;/P&gt;&lt;P&gt;if it doesn't run. check the "(source=source1 OR source=source2)" condition and check if the regex you used is correct for those events..&lt;/P&gt;&lt;P&gt;Anyway, probably host could be more interesting than source.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 10:07:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593574#M76591</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-04-13T10:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Splunk log</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593855#M76612</link>
      <description>&lt;P&gt;Many thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I have other question in Comunity, if you are free please help me take a look on that:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-caculate-percentage-of-memory-used-value-in-each-message/m-p/593854#M76611" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-caculate-percentage-of-memory-used-value-in-each-message/m-p/593854#M76611&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 03:22:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-max-memory-used-value-in-each-message-and-create-time/m-p/593855#M76612</guid>
      <dc:creator>hungln9</dc:creator>
      <dc:date>2022-04-15T03:22:48Z</dc:date>
    </item>
  </channel>
</rss>

