<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Correlate multiple events, extract fields, output to table in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511083#M143147</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224124"&gt;@iulianbadea&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Based on&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184221"&gt;@to4kawa&lt;/a&gt;&amp;nbsp;'s approach and your sample data,&amp;nbsp; I edited the SPL slightly:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="test a1314456-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 961
test a1314456-cfef-11ea-a30e-962481bd1187 End Execution
test a1314456-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.2524148670490831
test a1314456-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.5367236440069973
test a1314456-cfef-11ea-a30e-962481bd1187 Query Status: Success
test a1314456-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843870}}
test a1314456-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.7129632540745661
test a1314456-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain
test a1314456-cfef-11ea-a30e-962481bd1187 Begin Execution
test a04e872e-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 960
test a04e872e-cfef-11ea-a30e-962481bd1187 End Execution
test a04e872e-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.1855176850222051
test a04e872e-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.4926855160156265
test a04e872e-cfef-11ea-a30e-962481bd1187 Query Status: Success
test a04e872e-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843868}}
test a04e872e-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.6907656920375302
test a04e872e-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain
test a04e872e-cfef-11ea-a30e-962481bd1187 Begin Execution
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 959
test 9f626fb0-cfef-11ea-a30e-962481bd1187 End Execution
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.2467742280568928
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.5091846379218623
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Query Status: Success
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843867}}
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.7355797099880874
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Begin Execution
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 958
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 End Execution
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.328197255032137
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.542056486941874
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Query Status: Success
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843865}}
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.784138589981012
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Begin Execution"
| multikv noheader=t
| table _raw
| rename COMMENT as "this is sample"
| rex "(?&amp;lt;common&amp;gt;\w+)\s(?&amp;lt;ID&amp;gt;\S+)\s(?&amp;lt;messages&amp;gt;.*)"
| rex field=messages "(?&amp;lt;field&amp;gt;.*):? (?&amp;lt;value&amp;gt;\S+)"
| eval {field}=value
| fields - field value messages

| rename "Query Status:" as Query_status
| rename "Query Elapsed Time" as Query_time
| rename "Total Execution Time:" as Total_time
| chart values(Query_status), values(Query_time), values(Total_time) by ID&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jul 2020 10:23:19 GMT</pubDate>
    <dc:creator>rnowitzki</dc:creator>
    <dc:date>2020-07-27T10:23:19Z</dc:date>
    <item>
      <title>Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511064#M143140</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to correlate some events that have same field and then to output the results to a table.&lt;/P&gt;&lt;P&gt;Example of raw data:&lt;/P&gt;&lt;P&gt;test d34e9bca-cfd9-11ea-9873-962481bd1187 Overall Executions in this runtime: 295&lt;BR /&gt;test d34e9bca-cfd9-11ea-9873-962481bd1187 End Execution&lt;BR /&gt;test d34e9bca-cfd9-11ea-9873-962481bd1187 Total Execution Time: 1.6354868500493467&lt;BR /&gt;test d34e9bca-cfd9-11ea-9873-962481bd1187 Query Elapsed Time 0.5768028399907053&lt;BR /&gt;test d34e9bca-cfd9-11ea-9873-962481bd1187 Query Status: Success&lt;BR /&gt;test d34e9bca-cfd9-11ea-9873-962481bd1187 Query Result: {"EXPR$0":{"0":1595834505}}&lt;BR /&gt;test d34e9bca-cfd9-11ea-9873-962481bd1187 Connection elapsed time: 1.056466632988304&lt;BR /&gt;test d34e9bca-cfd9-11ea-9873-962481bd1187 Establishing connection as: user@domain&lt;BR /&gt;test d34e9bca-cfd9-11ea-9873-962481bd1187 Begin Execution&lt;/P&gt;&lt;P&gt;For each "test" I have 9 events in Splunk.&lt;/P&gt;&lt;P&gt;I want to output to a table like:&lt;/P&gt;&lt;P&gt;ID, Query_status, Query_time, Total_time&lt;/P&gt;&lt;P&gt;d34e9bca-cfd9-11ea-9873-962481bd1187,&amp;nbsp;Success,&amp;nbsp;0.57,&amp;nbsp;1.63&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which would be the best method to accomplish this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 07:31:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511064#M143140</guid>
      <dc:creator>iulianbadea</dc:creator>
      <dc:date>2020-07-27T07:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511070#M143141</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224124"&gt;@iulianbadea&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Do you have already fields for query status, query time and total time?&lt;BR /&gt;&lt;BR /&gt;If yes, this here is a good starting point:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| transaction id
| fields id, query_status, query_time, total_time&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;You could finetune it with&amp;nbsp;&lt;SPAN&gt;startswith="Begin Execution" endswith="End Execution" (if applicable) as described &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/SearchReference/Transaction" target="_self"&gt;here&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;Let us know if you need additional help to extract the fields.&lt;BR /&gt;&lt;BR /&gt;Hope it helps&lt;BR /&gt;&lt;BR /&gt;BR&lt;BR /&gt;Ralph&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 08:06:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511070#M143141</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2020-07-27T08:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511073#M143142</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64317"&gt;@rnowitzki&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I've tried:&lt;/P&gt;&lt;P&gt;index=myindex sourcetype=mysource&lt;/P&gt;&lt;P&gt;| rex field=_raw "test (?&amp;lt;id&amp;gt;.*) Begin Execution"&lt;BR /&gt;| rex field=_raw "Query Status: (?&amp;lt;query_status&amp;gt;.*)"&lt;BR /&gt;| rex field=_raw "Query Elapsed Time (?&amp;lt;query_time&amp;gt;.*)"&lt;BR /&gt;| rex field=_raw "Total Execution Time: (?&amp;lt;total_time&amp;gt;.*)"&lt;BR /&gt;| transaction id&lt;BR /&gt;| table id, query_status, query_time, total_time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it only shows me the "id", the rest of the fields are empty.&lt;/P&gt;&lt;P&gt;Not sure if I can use&amp;nbsp;&lt;SPAN&gt;startswith="Begin Execution" endswith="End Execution" because I don't have timestamps on these events, they are sent to Splunk in bulk each 10 mins, having as timestamps the time when were sent.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 08:19:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511073#M143142</guid>
      <dc:creator>iulianbadea</dc:creator>
      <dc:date>2020-07-27T08:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511076#M143143</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="test d34e9bca-cfd9-11ea-9873-962481bd1187 Overall Executions in this runtime: 295
test d34e9bca-cfd9-11ea-9873-962481bd1187 End Execution
test d34e9bca-cfd9-11ea-9873-962481bd1187 Total Execution Time: 1.6354868500493467
test d34e9bca-cfd9-11ea-9873-962481bd1187 Query Elapsed Time 0.5768028399907053
test d34e9bca-cfd9-11ea-9873-962481bd1187 Query Status: Success
test d34e9bca-cfd9-11ea-9873-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595834505}}
test d34e9bca-cfd9-11ea-9873-962481bd1187 Connection elapsed time: 1.056466632988304
test d34e9bca-cfd9-11ea-9873-962481bd1187 Establishing connection as: user@domain
test d34e9bca-cfd9-11ea-9873-962481bd1187 Begin Execution"
| multikv noheader=t
| table _raw
| rename COMMENT as "this is sample"
| rex "(?&amp;lt;common&amp;gt;\w+)\s(?&amp;lt;ID&amp;gt;\S+)\s(?&amp;lt;messages&amp;gt;.*)"
| rex field=messages "(?&amp;lt;field&amp;gt;.*):? (?&amp;lt;value&amp;gt;\S+)"
| eval {field}=value
| fields - field value messages
| stats values(*) as * by common
| rename "Query Status:" as Query_status
| rename "Query Elapsed Time" as Query_time
| rename "Total Execution Time:" as Total_time
| table ID, Query_status, Query_time, Total_time&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 27 Jul 2020 08:53:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511076#M143143</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-27T08:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511080#M143144</link>
      <description>&lt;P&gt;Wow, thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184221"&gt;@to4kawa&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Almost there...seems that all the columns are sorted and not correlated.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iulianbadea_0-1595841889336.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9883i320B5C23C2CDA563/image-size/medium?v=v2&amp;amp;px=400" role="button" title="iulianbadea_0-1595841889336.png" alt="iulianbadea_0-1595841889336.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I mean for the first ID I have different connection times.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 09:26:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511080#M143144</guid>
      <dc:creator>iulianbadea</dc:creator>
      <dc:date>2020-07-27T09:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511081#M143145</link>
      <description>&lt;P&gt;your sample is not enough information.You should be the first to tell us.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 10:09:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511081#M143145</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-27T10:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511082#M143146</link>
      <description>&lt;P&gt;| makeresults&lt;BR /&gt;| eval _raw="test a1314456-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 961&lt;BR /&gt;test a1314456-cfef-11ea-a30e-962481bd1187 End Execution&lt;BR /&gt;test a1314456-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.2524148670490831&lt;BR /&gt;test a1314456-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.5367236440069973&lt;BR /&gt;test a1314456-cfef-11ea-a30e-962481bd1187 Query Status: Success&lt;BR /&gt;test a1314456-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843870}}&lt;BR /&gt;test a1314456-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.7129632540745661&lt;BR /&gt;test a1314456-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain&lt;BR /&gt;test a1314456-cfef-11ea-a30e-962481bd1187 Begin Execution&lt;BR /&gt;test a04e872e-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 960&lt;BR /&gt;test a04e872e-cfef-11ea-a30e-962481bd1187 End Execution&lt;BR /&gt;test a04e872e-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.1855176850222051&lt;BR /&gt;test a04e872e-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.4926855160156265&lt;BR /&gt;test a04e872e-cfef-11ea-a30e-962481bd1187 Query Status: Success&lt;BR /&gt;test a04e872e-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843868}}&lt;BR /&gt;test a04e872e-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.6907656920375302&lt;BR /&gt;test a04e872e-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain&lt;BR /&gt;test a04e872e-cfef-11ea-a30e-962481bd1187 Begin Execution&lt;BR /&gt;test 9f626fb0-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 959&lt;BR /&gt;test 9f626fb0-cfef-11ea-a30e-962481bd1187 End Execution&lt;BR /&gt;test 9f626fb0-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.2467742280568928&lt;BR /&gt;test 9f626fb0-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.5091846379218623&lt;BR /&gt;test 9f626fb0-cfef-11ea-a30e-962481bd1187 Query Status: Success&lt;BR /&gt;test 9f626fb0-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843867}}&lt;BR /&gt;test 9f626fb0-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.7355797099880874&lt;BR /&gt;test 9f626fb0-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain&lt;BR /&gt;test 9f626fb0-cfef-11ea-a30e-962481bd1187 Begin Execution&lt;BR /&gt;test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 958&lt;BR /&gt;test 9e69ea5c-cfef-11ea-a30e-962481bd1187 End Execution&lt;BR /&gt;test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.328197255032137&lt;BR /&gt;test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.542056486941874&lt;BR /&gt;test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Query Status: Success&lt;BR /&gt;test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843865}}&lt;BR /&gt;test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.784138589981012&lt;BR /&gt;test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain&lt;BR /&gt;test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Begin Execution"&lt;BR /&gt;| multikv noheader=t&lt;BR /&gt;| table _raw&lt;BR /&gt;| rename COMMENT as "this is sample"&lt;BR /&gt;| rex "(?&amp;lt;common&amp;gt;\w+)\s(?&amp;lt;ID&amp;gt;\S+)\s(?&amp;lt;messages&amp;gt;.*)"&lt;BR /&gt;| rex field=messages "(?&amp;lt;field&amp;gt;.*):? (?&amp;lt;value&amp;gt;\S+)"&lt;BR /&gt;| eval {field}=value&lt;BR /&gt;| fields - field value messages&lt;BR /&gt;| stats values(*) as * by common&lt;BR /&gt;| rename "Query Status:" as Query_status&lt;BR /&gt;| rename "Query Elapsed Time" as Query_time&lt;BR /&gt;| rename "Total Execution Time:" as Total_time&lt;BR /&gt;| table ID, Query_status, Query_time, Total_time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are 4 full events, maybe it's clear now what I'm trying to say. All the columns are sorted/scrambled.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 10:11:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511082#M143146</guid>
      <dc:creator>iulianbadea</dc:creator>
      <dc:date>2020-07-27T10:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511083#M143147</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224124"&gt;@iulianbadea&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Based on&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184221"&gt;@to4kawa&lt;/a&gt;&amp;nbsp;'s approach and your sample data,&amp;nbsp; I edited the SPL slightly:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="test a1314456-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 961
test a1314456-cfef-11ea-a30e-962481bd1187 End Execution
test a1314456-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.2524148670490831
test a1314456-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.5367236440069973
test a1314456-cfef-11ea-a30e-962481bd1187 Query Status: Success
test a1314456-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843870}}
test a1314456-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.7129632540745661
test a1314456-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain
test a1314456-cfef-11ea-a30e-962481bd1187 Begin Execution
test a04e872e-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 960
test a04e872e-cfef-11ea-a30e-962481bd1187 End Execution
test a04e872e-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.1855176850222051
test a04e872e-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.4926855160156265
test a04e872e-cfef-11ea-a30e-962481bd1187 Query Status: Success
test a04e872e-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843868}}
test a04e872e-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.6907656920375302
test a04e872e-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain
test a04e872e-cfef-11ea-a30e-962481bd1187 Begin Execution
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 959
test 9f626fb0-cfef-11ea-a30e-962481bd1187 End Execution
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.2467742280568928
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.5091846379218623
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Query Status: Success
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843867}}
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.7355797099880874
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain
test 9f626fb0-cfef-11ea-a30e-962481bd1187 Begin Execution
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Overall Executions in this runtime: 958
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 End Execution
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Total Execution Time: 1.328197255032137
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Query Elapsed Time 0.542056486941874
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Query Status: Success
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Query Result: {\"EXPR$0\":{\"0\":1595843865}}
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Connection elapsed time: 0.784138589981012
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Establishing connection as: user@domain
test 9e69ea5c-cfef-11ea-a30e-962481bd1187 Begin Execution"
| multikv noheader=t
| table _raw
| rename COMMENT as "this is sample"
| rex "(?&amp;lt;common&amp;gt;\w+)\s(?&amp;lt;ID&amp;gt;\S+)\s(?&amp;lt;messages&amp;gt;.*)"
| rex field=messages "(?&amp;lt;field&amp;gt;.*):? (?&amp;lt;value&amp;gt;\S+)"
| eval {field}=value
| fields - field value messages

| rename "Query Status:" as Query_status
| rename "Query Elapsed Time" as Query_time
| rename "Total Execution Time:" as Total_time
| chart values(Query_status), values(Query_time), values(Total_time) by ID&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 10:23:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511083#M143147</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2020-07-27T10:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511111#M143152</link>
      <description>&lt;P&gt;Thank you both!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 13:08:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511111#M143152</guid>
      <dc:creator>iulianbadea</dc:creator>
      <dc:date>2020-07-27T13:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511218#M143202</link>
      <description>&lt;P&gt;Can you please help once more? Timestamp is also present now:&lt;/P&gt;&lt;P&gt;Sample data:&lt;/P&gt;&lt;P&gt;2020-07-27T17:55:40.990228+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Begin Execution&lt;BR /&gt;2020-07-27T17:55:40.990270+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Establishing connection as: user@domain&lt;BR /&gt;2020-07-27T17:55:41.677376+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Connection elapsed time: 0.6870694829999948&lt;BR /&gt;2020-07-27T17:55:42.149634+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Query Result: {\"EXPR$0\":{\"0\":1595872451}}&lt;BR /&gt;2020-07-27T17:55:42.149669+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Query Status: Success&lt;BR /&gt;2020-07-27T17:55:42.149685+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Query Elapsed Time 0.4722382859999996&lt;BR /&gt;2020-07-27T17:55:42.218875+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Total Execution Time: 1.2286392209999946&lt;BR /&gt;2020-07-27T17:55:42.218918+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 End Execution&lt;BR /&gt;2020-07-27T17:55:42.218952+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Overall Executions in this runtime: 20&lt;BR /&gt;2020-07-27T17:55:42.522960+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Begin Execution&lt;BR /&gt;2020-07-27T17:55:42.523002+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Establishing connection as: user@domain&lt;BR /&gt;2020-07-27T17:55:43.120431+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Connection elapsed time: 0.5973759029999997&lt;BR /&gt;2020-07-27T17:55:43.690096+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Query Result: {\"EXPR$0\":{\"0\":1595872453}}&lt;BR /&gt;2020-07-27T17:55:43.690128+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Query Status: Success&lt;BR /&gt;2020-07-27T17:55:43.690144+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Query Elapsed Time 0.5696396760000013&lt;BR /&gt;2020-07-27T17:55:43.747893+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Total Execution Time: 1.224972496999996&lt;BR /&gt;2020-07-27T17:55:43.747934+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 End Execution&lt;BR /&gt;2020-07-27T17:55:43.747947+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Overall Executions in this runtime: 21&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 20:10:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511218#M143202</guid>
      <dc:creator>iulianbadea</dc:creator>
      <dc:date>2020-07-27T20:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511223#M143235</link>
      <description>&lt;P&gt;&lt;FONT&gt;| makeresults&lt;BR /&gt;| eval _raw="2020-07-27T17:55:40.990228+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Begin Execution&lt;BR /&gt;2020-07-27T17:55:40.990270+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Establishing connection as: user@domain&lt;BR /&gt;2020-07-27T17:55:41.677376+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Connection elapsed time: 0.6870694829999948&lt;BR /&gt;2020-07-27T17:55:42.149634+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Query Result: {\"EXPR$0\":{\"0\":1595872451}}&lt;BR /&gt;2020-07-27T17:55:42.149669+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Query Status: Success&lt;BR /&gt;2020-07-27T17:55:42.149685+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Query Elapsed Time 0.4722382859999996&lt;BR /&gt;2020-07-27T17:55:42.218875+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Total Execution Time: 1.2286392209999946&lt;BR /&gt;2020-07-27T17:55:42.218918+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 End Execution&lt;BR /&gt;2020-07-27T17:55:42.218952+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Overall Executions in this runtime: 20&lt;BR /&gt;2020-07-27T17:55:42.522960+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Begin Execution&lt;BR /&gt;2020-07-27T17:55:42.523002+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Establishing connection as: user@domain&lt;BR /&gt;2020-07-27T17:55:43.120431+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Connection elapsed time: 0.5973759029999997&lt;BR /&gt;2020-07-27T17:55:43.690096+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Query Result: {\"EXPR$0\":{\"0\":1595872453}}&lt;BR /&gt;2020-07-27T17:55:43.690128+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Query Status: Success&lt;BR /&gt;2020-07-27T17:55:43.690144+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Query Elapsed Time 0.5696396760000013&lt;BR /&gt;2020-07-27T17:55:43.747893+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Total Execution Time: 1.224972496999996&lt;BR /&gt;2020-07-27T17:55:43.747934+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 End Execution&lt;BR /&gt;2020-07-27T17:55:43.747947+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Overall Executions in this runtime: 21"&lt;BR /&gt;| multikv noheader=t&lt;BR /&gt;| table _raw&lt;BR /&gt;| rename COMMENT as "this is sample"&lt;BR /&gt;| rex "\d+ (?&amp;lt;common&amp;gt;[^ ]+)\W(?&amp;lt;ID&amp;gt;\S+)\s(?&amp;lt;messages&amp;gt;.*)"&lt;BR /&gt;| rex field=messages "(?&amp;lt;field&amp;gt;.*):? (?&amp;lt;value&amp;gt;\S+)"&lt;BR /&gt;| eval {field}=value&lt;BR /&gt;| fields - field value message&lt;BR /&gt;| rename "Query Status:" as Query_status&lt;BR /&gt;| rename "Query Elapsed Time" as Query_time&lt;BR /&gt;| rename "Total Execution Time:" as Total_time&lt;BR /&gt;| chart values(Query_status), values(Query_time), values(Total_time) by ID&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 20:46:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511223#M143235</guid>
      <dc:creator>spitchika</dc:creator>
      <dc:date>2020-07-27T20:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: Correlate multiple events, extract fields, output to table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511227#M143236</link>
      <description>&lt;P&gt;&lt;FONT&gt;Try this...&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;| makeresults&lt;BR /&gt;| eval _raw="2020-07-27T17:55:40.990228+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Begin Execution&lt;BR /&gt;2020-07-27T17:55:40.990270+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Establishing connection as: user@domain&lt;BR /&gt;2020-07-27T17:55:41.677376+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Connection elapsed time: 0.6870694829999948&lt;BR /&gt;2020-07-27T17:55:42.149634+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Query Result: {\"EXPR$0\":{\"0\":1595872451}}&lt;BR /&gt;2020-07-27T17:55:42.149669+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Query Status: Success&lt;BR /&gt;2020-07-27T17:55:42.149685+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Query Elapsed Time 0.4722382859999996&lt;BR /&gt;2020-07-27T17:55:42.218875+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Total Execution Time: 1.2286392209999946&lt;BR /&gt;2020-07-27T17:55:42.218918+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 End Execution&lt;BR /&gt;2020-07-27T17:55:42.218952+00:00 test-test-test 62a14dc4-d032-11ea-a166-acde48001122 Overall Executions in this runtime: 20&lt;BR /&gt;2020-07-27T17:55:42.522960+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Begin Execution&lt;BR /&gt;2020-07-27T17:55:42.523002+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Establishing connection as: user@domain&lt;BR /&gt;2020-07-27T17:55:43.120431+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Connection elapsed time: 0.5973759029999997&lt;BR /&gt;2020-07-27T17:55:43.690096+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Query Result: {\"EXPR$0\":{\"0\":1595872453}}&lt;BR /&gt;2020-07-27T17:55:43.690128+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Query Status: Success&lt;BR /&gt;2020-07-27T17:55:43.690144+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Query Elapsed Time 0.5696396760000013&lt;BR /&gt;2020-07-27T17:55:43.747893+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Total Execution Time: 1.224972496999996&lt;BR /&gt;2020-07-27T17:55:43.747934+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 End Execution&lt;BR /&gt;2020-07-27T17:55:43.747947+00:00 test-test-test 638b2c5a-d032-11ea-a166-acde48001122 Overall Executions in this runtime: 21"&lt;BR /&gt;| multikv noheader=t&lt;BR /&gt;| table _raw&lt;BR /&gt;| rename COMMENT as "this is sample"&lt;BR /&gt;| rex "\d+ (?&amp;lt;common&amp;gt;[^ ]+)\W(?&amp;lt;ID&amp;gt;\S+)\s(?&amp;lt;messages&amp;gt;.*)"&lt;BR /&gt;| rex field=messages "(?&amp;lt;field&amp;gt;.*):? (?&amp;lt;value&amp;gt;\S+)"&lt;BR /&gt;| eval {field}=value&lt;BR /&gt;| fields - field value message&lt;BR /&gt;| rename "Query Status:" as Query_status&lt;BR /&gt;| rename "Query Elapsed Time" as Query_time&lt;BR /&gt;| rename "Total Execution Time:" as Total_time&lt;BR /&gt;| chart values(Query_status), values(Query_time), values(Total_time) by ID&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 20:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Correlate-multiple-events-extract-fields-output-to-table/m-p/511227#M143236</guid>
      <dc:creator>spitchika</dc:creator>
      <dc:date>2020-07-27T20:48:47Z</dc:date>
    </item>
  </channel>
</rss>

