<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to fetch the start and the End Time from row logs in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-start-and-the-End-Time-from-row-logs/m-p/656271#M54058</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;How can I fetch the start and end time from below logs:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;2023-08-30&lt;/SPAN&gt; &lt;SPAN class=""&gt;00:29:00.018&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt; ] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;pool-3-thread-1&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;ReadControlFileImpl&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Reading&lt;/SPAN&gt; &lt;SPAN class=""&gt;Control-File&lt;/SPAN&gt; &lt;SPAN class=""&gt;/absin/CARS.HIERCTR&lt;/SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;D082923&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;T002302&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;2023-08-30 07:43:29.020&lt;/STRONG&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;INFO&lt;SPAN&gt; ] [&lt;/SPAN&gt;Thread-18&lt;SPAN&gt;] &lt;/SPAN&gt;FileEventCreator - &lt;SPAN class=""&gt;Completed Settlement file processing,&lt;/SPAN&gt; TRIM.UNB.D082923.T045920 records processed: 13283520&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I want this start time and end time &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;can someone help me with query&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;my current query:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;index="abc"sourcetype ="600000304_gg_abs_ipc2" source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log"&lt;BR /&gt;"Reading Control-File /absin/CARS.HIERCTR."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 31 Aug 2023 13:38:51 GMT</pubDate>
    <dc:creator>aditsss</dc:creator>
    <dc:date>2023-08-31T13:38:51Z</dc:date>
    <item>
      <title>How to fetch the start and the End Time from row logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-start-and-the-End-Time-from-row-logs/m-p/656271#M54058</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;How can I fetch the start and end time from below logs:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;2023-08-30&lt;/SPAN&gt; &lt;SPAN class=""&gt;00:29:00.018&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt; ] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;pool-3-thread-1&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;ReadControlFileImpl&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Reading&lt;/SPAN&gt; &lt;SPAN class=""&gt;Control-File&lt;/SPAN&gt; &lt;SPAN class=""&gt;/absin/CARS.HIERCTR&lt;/SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;D082923&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN class=""&gt;T002302&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;2023-08-30 07:43:29.020&lt;/STRONG&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;INFO&lt;SPAN&gt; ] [&lt;/SPAN&gt;Thread-18&lt;SPAN&gt;] &lt;/SPAN&gt;FileEventCreator - &lt;SPAN class=""&gt;Completed Settlement file processing,&lt;/SPAN&gt; TRIM.UNB.D082923.T045920 records processed: 13283520&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I want this start time and end time &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;can someone help me with query&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;my current query:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;index="abc"sourcetype ="600000304_gg_abs_ipc2" source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log"&lt;BR /&gt;"Reading Control-File /absin/CARS.HIERCTR."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 13:38:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-start-and-the-End-Time-from-row-logs/m-p/656271#M54058</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-08-31T13:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the start and the End Time from row logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-start-and-the-End-Time-from-row-logs/m-p/656287#M54060</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you are receiving those two lines in the same event you could try to use something like this :&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="abc"sourcetype ="600000304_gg_abs_ipc2" source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log"
"Reading Control-File /absin/CARS.HIERCTR."
| rex "(?&amp;lt;starttime&amp;gt;.*?)\s\[.*\s\].*[\r\n]+(?&amp;lt;endtime&amp;gt;.*?)\s\[.*\s\].*"&lt;/LI-CODE&gt;&lt;P&gt;This gave me the following results :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GaetanVP_0-1693495483320.png" style="width: 889px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27024i51C77809E0404744/image-dimensions/889x189?v=v2" width="889" height="189" role="button" title="GaetanVP_0-1693495483320.png" alt="GaetanVP_0-1693495483320.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;BR /&gt;GaetanVP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 15:25:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-start-and-the-End-Time-from-row-logs/m-p/656287#M54060</guid>
      <dc:creator>GaetanVP</dc:creator>
      <dc:date>2023-08-31T15:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the start and the End Time from row logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-start-and-the-End-Time-from-row-logs/m-p/656290#M54061</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried below query not getting any result&lt;/P&gt;&lt;P&gt;index="abcsourcetype ="600000304_gg_abs_ipc2" source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log"&lt;BR /&gt;"Reading Control-File /absin/CARS.HIERCTR."&lt;BR /&gt;| rex "(?&amp;lt;starttime&amp;gt;.*?)\s\[.*\s\].*[\r\n]+(?&amp;lt;endtime&amp;gt;.*?)\s\[.*\s\].*"| table starttime endtime&lt;/P&gt;&lt;P&gt;also for end process logs are these:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;2023-08-30&lt;/SPAN&gt; &lt;SPAN class=""&gt;04:09:30.458&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt; ] [&lt;/SPAN&gt;&lt;SPAN class=""&gt;Thread-40&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;FileEventCreator&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Completed&lt;/SPAN&gt; &lt;SPAN class=""&gt;Settlement&lt;/SPAN&gt; &lt;SPAN class=""&gt;file&lt;/SPAN&gt; &lt;SPAN class=""&gt;processing&lt;/SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN class=""&gt;CARS.HIER.D082923.T002302&lt;/SPAN&gt; &lt;SPAN class=""&gt;records&lt;/SPAN&gt; &lt;SPAN class=""&gt;processed:&lt;/SPAN&gt; &lt;SPAN class=""&gt;161076&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;&amp;nbsp;please guide&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 15:38:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-start-and-the-End-Time-from-row-logs/m-p/656290#M54061</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-08-31T15:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the start and the End Time from row logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-start-and-the-End-Time-from-row-logs/m-p/656315#M54066</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;&amp;nbsp;could you please guide.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 19:45:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-start-and-the-End-Time-from-row-logs/m-p/656315#M54066</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2023-08-31T19:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to fetch the start and the End Time from row logs</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-start-and-the-End-Time-from-row-logs/m-p/656378#M54071</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I’m expecting that those are two different events and with your sample query you get only the 1st event not both? If this is true, you must first implement a SPL query which result contains both events. Then there must be something common on those events to connect those together. On your example events I can’t see anything like that! Probably you must find some other logs which you could use to combine all events on one transaction together?&lt;/P&gt;&lt;P&gt;Only common factor between those event are&amp;nbsp;&lt;SPAN&gt;D082923, but it seems to be part of file name or something? I assume that it’s using as this on many transactions and cannot use as identity only on transaction?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 07:51:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-fetch-the-start-and-the-End-Time-from-row-logs/m-p/656378#M54071</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-09-01T07:51:48Z</dc:date>
    </item>
  </channel>
</rss>

