<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CommonBaseEvent treatment in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/CommonBaseEvent-treatment/m-p/475002#M8301</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;I receiving some event from our Monitoring Agent tool (from the editor Dassault Systemes) through Common Base Event format like:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;PRE&gt;&lt;CODE&gt;  &amp;lt;extendedDataElements name="status" type="string"&amp;gt;
    &amp;lt;values&amp;gt;0&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;extendedDataElements name="elapsed" type="string"&amp;gt;
    &amp;lt;values&amp;gt;203&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;extendedDataElements name="_period" type="string"&amp;gt;
    &amp;lt;values&amp;gt;300&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;extendedDataElements name="connection" type="string"&amp;gt;
    &amp;lt;values&amp;gt;47&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;extendedDataElements name="logoutTime" type="string"&amp;gt;
    &amp;lt;values&amp;gt;62&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;extendedDataElements name="getLoginPageTime" type="string"&amp;gt;
    &amp;lt;values&amp;gt;78&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;sourceComponentId componentType="ProductName" instanceId="3dpassport_TEST1" component="serviceHealthCheck" processId="" locationType="Hostname" location="io-ws-3de71ts" subComponent="" componentIdType="ProductName"/&amp;gt;
  &amp;lt;situation categoryName="ReportSituation"&amp;gt;
    &amp;lt;situationType reportCategory="LOG" xsi:type="ReportSituation" reasoningScope="INTERNAL"/&amp;gt;
  &amp;lt;/situation&amp;gt;
&amp;lt;/CommonBaseEvent&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I don't really understand how can I operate for example the "ELAPSED" extended elements and moreover be able to track his value evolution&lt;BR /&gt;
Any clue on your side?&lt;/P&gt;</description>
    <pubDate>Tue, 10 Sep 2019 15:31:55 GMT</pubDate>
    <dc:creator>benji00</dc:creator>
    <dc:date>2019-09-10T15:31:55Z</dc:date>
    <item>
      <title>CommonBaseEvent treatment</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/CommonBaseEvent-treatment/m-p/475002#M8301</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;I receiving some event from our Monitoring Agent tool (from the editor Dassault Systemes) through Common Base Event format like:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;PRE&gt;&lt;CODE&gt;  &amp;lt;extendedDataElements name="status" type="string"&amp;gt;
    &amp;lt;values&amp;gt;0&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;extendedDataElements name="elapsed" type="string"&amp;gt;
    &amp;lt;values&amp;gt;203&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;extendedDataElements name="_period" type="string"&amp;gt;
    &amp;lt;values&amp;gt;300&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;extendedDataElements name="connection" type="string"&amp;gt;
    &amp;lt;values&amp;gt;47&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;extendedDataElements name="logoutTime" type="string"&amp;gt;
    &amp;lt;values&amp;gt;62&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;extendedDataElements name="getLoginPageTime" type="string"&amp;gt;
    &amp;lt;values&amp;gt;78&amp;lt;/values&amp;gt;
  &amp;lt;/extendedDataElements&amp;gt;
  &amp;lt;sourceComponentId componentType="ProductName" instanceId="3dpassport_TEST1" component="serviceHealthCheck" processId="" locationType="Hostname" location="io-ws-3de71ts" subComponent="" componentIdType="ProductName"/&amp;gt;
  &amp;lt;situation categoryName="ReportSituation"&amp;gt;
    &amp;lt;situationType reportCategory="LOG" xsi:type="ReportSituation" reasoningScope="INTERNAL"/&amp;gt;
  &amp;lt;/situation&amp;gt;
&amp;lt;/CommonBaseEvent&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I don't really understand how can I operate for example the "ELAPSED" extended elements and moreover be able to track his value evolution&lt;BR /&gt;
Any clue on your side?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 15:31:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/CommonBaseEvent-treatment/m-p/475002#M8301</guid>
      <dc:creator>benji00</dc:creator>
      <dc:date>2019-09-10T15:31:55Z</dc:date>
    </item>
  </channel>
</rss>

