<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: search PID and list according to PID generated and killed time in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/search-PID-and-list-according-to-PID-generated-and-killed-time/m-p/521281#M17934</link>
    <description>&lt;P&gt;Can more than one process run concurrently?&lt;/P&gt;&lt;P&gt;2020-08-20 08:52:46, 760 XYZ_Processor/1.1.0 Application Process Completed&lt;/P&gt;&lt;P&gt;2020-08-20 08:51:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:50:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:47:46, 760 XYZ_Processor/1.1.0&amp;nbsp;Application Process Completed&lt;/P&gt;&lt;P&gt;2020-08-20 08:40:46, 760 XYZ_Processor/1.1.0 Application Process Id generated : 23232&lt;/P&gt;&lt;P&gt;2020-08-20 08:39:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:38:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:37:46, 760 XYZ_Processor/1.1.0 Application Process Id generated : 42343&lt;/P&gt;&lt;P&gt;If so, how do you identify which Process ID each&amp;nbsp;Application Process Completed is related to?&lt;/P&gt;</description>
    <pubDate>Thu, 24 Sep 2020 14:11:08 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2020-09-24T14:11:08Z</dc:date>
    <item>
      <title>search PID and list according to PID generated and killed time</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/search-PID-and-list-according-to-PID-generated-and-killed-time/m-p/521279#M17933</link>
      <description>&lt;P&gt;Hello Splunk Community,&lt;/P&gt;&lt;P&gt;I am kind of beginner in Splunk. Need help on a scenario&lt;/P&gt;&lt;P&gt;I have below example logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2020-08-20 08:52:46, 760 XYZ_Processor/1.1.0 Application Process Completed&lt;/P&gt;&lt;P&gt;2020-08-20 08:51:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:50:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:47:46, 760 XYZ_Processor/1.1.0 Application Process Id generated : 23232&lt;/P&gt;&lt;P&gt;2020-08-20 08:40:46, 760 XYZ_Processor/1.1.0 Application Process Completed&lt;/P&gt;&lt;P&gt;2020-08-20 08:39:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:38:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:37:46, 760 XYZ_Processor/1.1.0 Application Process Id generated : 42343&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want below results&lt;/P&gt;&lt;P&gt;PID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; START_TIME &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; END_TIME&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TIME_TAKEN&lt;/P&gt;&lt;P&gt;42343&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2020-08-20 08:37:46&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2020-08-20 08:40:46&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 03:00:00&lt;/P&gt;&lt;P&gt;23232&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2020-08-20 08:47:46&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2020-08-20 08:52:46&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 05:00:00&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could anyone help in this? I have to add PID as first field from the logs and print in first column and then start time and end time of the process and then the time taken. Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 13:57:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/search-PID-and-list-according-to-PID-generated-and-killed-time/m-p/521279#M17933</guid>
      <dc:creator>vijen2000</dc:creator>
      <dc:date>2020-09-24T13:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: search PID and list according to PID generated and killed time</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/search-PID-and-list-according-to-PID-generated-and-killed-time/m-p/521281#M17934</link>
      <description>&lt;P&gt;Can more than one process run concurrently?&lt;/P&gt;&lt;P&gt;2020-08-20 08:52:46, 760 XYZ_Processor/1.1.0 Application Process Completed&lt;/P&gt;&lt;P&gt;2020-08-20 08:51:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:50:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:47:46, 760 XYZ_Processor/1.1.0&amp;nbsp;Application Process Completed&lt;/P&gt;&lt;P&gt;2020-08-20 08:40:46, 760 XYZ_Processor/1.1.0 Application Process Id generated : 23232&lt;/P&gt;&lt;P&gt;2020-08-20 08:39:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:38:46, 760 XYZ_Processor/1.1.0 Random logs&lt;/P&gt;&lt;P&gt;2020-08-20 08:37:46, 760 XYZ_Processor/1.1.0 Application Process Id generated : 42343&lt;/P&gt;&lt;P&gt;If so, how do you identify which Process ID each&amp;nbsp;Application Process Completed is related to?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 14:11:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/search-PID-and-list-according-to-PID-generated-and-killed-time/m-p/521281#M17934</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-24T14:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: search PID and list according to PID generated and killed time</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/search-PID-and-list-according-to-PID-generated-and-killed-time/m-p/521284#M17935</link>
      <description>&lt;P&gt;@&lt;SPAN class="UserName lia-user-name lia-user-rank-Path-Finder"&gt;&lt;SPAN class="lia-link-navigation lia-page-link lia-link-disabled lia-user-name-link"&gt;&lt;SPAN class=""&gt;ITWhisperer&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks for response. Only one process run at a time.&lt;/P&gt;&lt;P&gt;Once process completes, we get the message "Application Process Completed" and then new id get created again like this&lt;/P&gt;&lt;P&gt;2020-08-20 08:40:46, 760 XYZ_Processor/1.1.0 Application Process Id generated : 23232&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 14:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/search-PID-and-list-according-to-PID-generated-and-killed-time/m-p/521284#M17935</guid>
      <dc:creator>vijen2000</dc:creator>
      <dc:date>2020-09-24T14:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: search PID and list according to PID generated and killed time</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/search-PID-and-list-according-to-PID-generated-and-killed-time/m-p/521292#M17936</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=... ("Application Process Completed" OR "Application Process Id generated"
| rex "Application Process Id generated : (?&amp;lt;id&amp;gt;\d+)"
| streamstats window=2 earliest(_time) as start earliest(id) as pid
| where isnull(id)
| eval time_taken=_time-start
| table pid start _time time_taken
| fieldformat start=strftime(start,"%Y-%m-%d %H:%M:%S")
| fieldformat time_taken=strftime(time_taken,"%H:%M:%S")&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 24 Sep 2020 14:37:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/search-PID-and-list-according-to-PID-generated-and-killed-time/m-p/521292#M17936</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-24T14:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: search PID and list according to PID generated and killed time</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/search-PID-and-list-according-to-PID-generated-and-killed-time/m-p/521307#M17937</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;It worked &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot buddy for swift response. Big thumps up to you&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 15:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/search-PID-and-list-according-to-PID-generated-and-killed-time/m-p/521307#M17937</guid>
      <dc:creator>vijen2000</dc:creator>
      <dc:date>2020-09-24T15:31:32Z</dc:date>
    </item>
  </channel>
</rss>

