<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to parse p4 logs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/529133#M149393</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t h"&gt;2020&lt;/SPAN&gt;/11/12&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:37:17&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pid&lt;/SPAN&gt; &lt;SPAN class="t"&gt;282689&lt;/SPAN&gt; &lt;SPAN class="t"&gt;compute&lt;/SPAN&gt; &lt;SPAN class="t"&gt;end&lt;/SPAN&gt; &lt;SPAN class="t"&gt;.028s&lt;/SPAN&gt; &lt;SPAN class="t"&gt;23&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;5us&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;32io&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0net&lt;/SPAN&gt; &lt;SPAN class="t"&gt;16472k&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0pf&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Perforce&lt;/SPAN&gt; &lt;SPAN class="t"&gt;server&lt;/SPAN&gt; &lt;SPAN class="t"&gt;info:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Server&lt;/SPAN&gt; &lt;SPAN class="t"&gt;network&lt;/SPAN&gt; &lt;SPAN class="t"&gt;estimates:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;files&lt;/SPAN&gt; &lt;SPAN class="t"&gt;added/updated/deleted=0/0/0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;bytes&lt;/SPAN&gt; &lt;SPAN class="t"&gt;added/updated=0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2020/11/12&lt;/SPAN&gt; &lt;SPAN class="t"&gt;08:53:57&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pid&lt;/SPAN&gt; &lt;SPAN class="t"&gt;249917&lt;/SPAN&gt;&amp;nbsp;xyz@admin-client-for-stag&amp;nbsp;&lt;SPAN class="t"&gt;127.0.0.1&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;p4/2018.1/LINUX26X86_64/1738923&lt;/SPAN&gt;&lt;SPAN&gt;] '&lt;/SPAN&gt;&lt;SPAN class="t"&gt;user-sizes&lt;/SPAN&gt; &lt;SPAN class="t"&gt;//ddc/...&lt;/SPAN&gt;&lt;SPAN&gt;' --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;lapse&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;98.5s&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rpc&lt;/SPAN&gt; &lt;SPAN class="t"&gt;msgs/size&lt;/SPAN&gt; &lt;SPAN class="t"&gt;in&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;out&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1814189/0mb&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;509mb&lt;/SPAN&gt; &lt;SPAN class="t"&gt;himarks&lt;/SPAN&gt; &lt;SPAN class="t"&gt;795800/318788&lt;/SPAN&gt; &lt;SPAN class="t"&gt;snd/rcv&lt;/SPAN&gt; &lt;SPAN class="t"&gt;92.8s/.000s&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;db.revhx&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;locks&lt;/SPAN&gt; &lt;SPAN class="t"&gt;read/write&lt;/SPAN&gt; &lt;SPAN class="t"&gt;1/0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rows&lt;/SPAN&gt; &lt;SPAN class="t"&gt;get&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;pos&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;scan&lt;/SPAN&gt; &lt;SPAN class="t"&gt;put&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;del&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1814190&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;+0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;2020/11/12&lt;/SPAN&gt; &lt;SPAN class="t"&gt;08:21:39&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pid&lt;/SPAN&gt; &lt;SPAN class="t"&gt;245315&lt;/SPAN&gt;&amp;nbsp;xyz&lt;SPAN class="t"&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/808"&gt;@Admin&lt;/a&gt;-client-for-stag&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;127.0.0.1&lt;/SPAN&gt; [&lt;SPAN class="t"&gt;p4/2018.1/LINUX26X86_64/1738923&lt;/SPAN&gt;] '&lt;SPAN class="t"&gt;user-sizes&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-s&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-a&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-b&lt;/SPAN&gt; &lt;SPAN class="t"&gt;512&lt;/SPAN&gt; &lt;SPAN class="t"&gt;//mapgrp/...&lt;/SPAN&gt;' --&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;lapse&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;106s&lt;/SPAN&gt; --&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;usage&lt;/SPAN&gt; &lt;SPAN class="t"&gt;51584&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;13969us&lt;/SPAN&gt; &lt;SPAN class="t"&gt;75284368&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;0io&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;0net&lt;/SPAN&gt; &lt;SPAN class="t"&gt;8832k&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0pf&lt;/SPAN&gt; --&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;db.rev&lt;/SPAN&gt; --&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pages&lt;/SPAN&gt; &lt;SPAN class="t"&gt;in&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;out&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;cached&lt;/SPAN&gt; &lt;SPAN class="t"&gt;4704508&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;96&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;2020/11/12 08:14:10 pid 243592&amp;nbsp;yyyz@admin-client-for-stag&amp;nbsp;127.0.0.1 [p4/2018.1/LINUX26X86_64/1738923] 'user-sizes -s -a -b 512 //projects/...' --- &lt;SPAN class="t a"&gt;lapse&lt;/SPAN&gt; 80.4s --- usage 38774+9874us 49562128+0io 0+0net 8832k 0pf --- db.rev --- pages in+out+cached 3374543+0+96&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;I have logs which shows lapse in seconds , they are several other logs along with this , i want to extract if logs pattern contains lapse and if lapse is greater than 100s ,and then print "&lt;A href="mailto:p4admin@admin-client-for-stag-21&amp;quot;" target="_blank" rel="noopener"&gt;xyz@admin-client-for-stag-21"&lt;/A&gt;&amp;nbsp;who is the user who did this change ,may be extract only &lt;/SPAN&gt;&lt;/P&gt;&lt;LI-SPOILER&gt;xyz&lt;/LI-SPOILER&gt;&lt;P&gt;user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Any help ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Nov 2020 13:19:24 GMT</pubDate>
    <dc:creator>vinodarokiya</dc:creator>
    <dc:date>2020-11-12T13:19:24Z</dc:date>
    <item>
      <title>How to parse p4 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/529133#M149393</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t h"&gt;2020&lt;/SPAN&gt;/11/12&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:37:17&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pid&lt;/SPAN&gt; &lt;SPAN class="t"&gt;282689&lt;/SPAN&gt; &lt;SPAN class="t"&gt;compute&lt;/SPAN&gt; &lt;SPAN class="t"&gt;end&lt;/SPAN&gt; &lt;SPAN class="t"&gt;.028s&lt;/SPAN&gt; &lt;SPAN class="t"&gt;23&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;5us&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;32io&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0net&lt;/SPAN&gt; &lt;SPAN class="t"&gt;16472k&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0pf&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Perforce&lt;/SPAN&gt; &lt;SPAN class="t"&gt;server&lt;/SPAN&gt; &lt;SPAN class="t"&gt;info:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Server&lt;/SPAN&gt; &lt;SPAN class="t"&gt;network&lt;/SPAN&gt; &lt;SPAN class="t"&gt;estimates:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;files&lt;/SPAN&gt; &lt;SPAN class="t"&gt;added/updated/deleted=0/0/0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;bytes&lt;/SPAN&gt; &lt;SPAN class="t"&gt;added/updated=0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2020/11/12&lt;/SPAN&gt; &lt;SPAN class="t"&gt;08:53:57&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pid&lt;/SPAN&gt; &lt;SPAN class="t"&gt;249917&lt;/SPAN&gt;&amp;nbsp;xyz@admin-client-for-stag&amp;nbsp;&lt;SPAN class="t"&gt;127.0.0.1&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;p4/2018.1/LINUX26X86_64/1738923&lt;/SPAN&gt;&lt;SPAN&gt;] '&lt;/SPAN&gt;&lt;SPAN class="t"&gt;user-sizes&lt;/SPAN&gt; &lt;SPAN class="t"&gt;//ddc/...&lt;/SPAN&gt;&lt;SPAN&gt;' --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;lapse&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;98.5s&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rpc&lt;/SPAN&gt; &lt;SPAN class="t"&gt;msgs/size&lt;/SPAN&gt; &lt;SPAN class="t"&gt;in&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;out&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1814189/0mb&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;509mb&lt;/SPAN&gt; &lt;SPAN class="t"&gt;himarks&lt;/SPAN&gt; &lt;SPAN class="t"&gt;795800/318788&lt;/SPAN&gt; &lt;SPAN class="t"&gt;snd/rcv&lt;/SPAN&gt; &lt;SPAN class="t"&gt;92.8s/.000s&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;db.revhx&lt;/SPAN&gt;&lt;SPAN&gt; --&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;locks&lt;/SPAN&gt; &lt;SPAN class="t"&gt;read/write&lt;/SPAN&gt; &lt;SPAN class="t"&gt;1/0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rows&lt;/SPAN&gt; &lt;SPAN class="t"&gt;get&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;pos&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;scan&lt;/SPAN&gt; &lt;SPAN class="t"&gt;put&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;del&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1814190&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;+0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;2020/11/12&lt;/SPAN&gt; &lt;SPAN class="t"&gt;08:21:39&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pid&lt;/SPAN&gt; &lt;SPAN class="t"&gt;245315&lt;/SPAN&gt;&amp;nbsp;xyz&lt;SPAN class="t"&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/808"&gt;@Admin&lt;/a&gt;-client-for-stag&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;127.0.0.1&lt;/SPAN&gt; [&lt;SPAN class="t"&gt;p4/2018.1/LINUX26X86_64/1738923&lt;/SPAN&gt;] '&lt;SPAN class="t"&gt;user-sizes&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-s&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-a&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-b&lt;/SPAN&gt; &lt;SPAN class="t"&gt;512&lt;/SPAN&gt; &lt;SPAN class="t"&gt;//mapgrp/...&lt;/SPAN&gt;' --&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;lapse&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;106s&lt;/SPAN&gt; --&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;usage&lt;/SPAN&gt; &lt;SPAN class="t"&gt;51584&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;13969us&lt;/SPAN&gt; &lt;SPAN class="t"&gt;75284368&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;0io&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;0net&lt;/SPAN&gt; &lt;SPAN class="t"&gt;8832k&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0pf&lt;/SPAN&gt; --&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;db.rev&lt;/SPAN&gt; --&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pages&lt;/SPAN&gt; &lt;SPAN class="t"&gt;in&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;out&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;cached&lt;/SPAN&gt; &lt;SPAN class="t"&gt;4704508&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;96&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;2020/11/12 08:14:10 pid 243592&amp;nbsp;yyyz@admin-client-for-stag&amp;nbsp;127.0.0.1 [p4/2018.1/LINUX26X86_64/1738923] 'user-sizes -s -a -b 512 //projects/...' --- &lt;SPAN class="t a"&gt;lapse&lt;/SPAN&gt; 80.4s --- usage 38774+9874us 49562128+0io 0+0net 8832k 0pf --- db.rev --- pages in+out+cached 3374543+0+96&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;I have logs which shows lapse in seconds , they are several other logs along with this , i want to extract if logs pattern contains lapse and if lapse is greater than 100s ,and then print "&lt;A href="mailto:p4admin@admin-client-for-stag-21&amp;quot;" target="_blank" rel="noopener"&gt;xyz@admin-client-for-stag-21"&lt;/A&gt;&amp;nbsp;who is the user who did this change ,may be extract only &lt;/SPAN&gt;&lt;/P&gt;&lt;LI-SPOILER&gt;xyz&lt;/LI-SPOILER&gt;&lt;P&gt;user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Any help ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 13:19:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/529133#M149393</guid>
      <dc:creator>vinodarokiya</dc:creator>
      <dc:date>2020-11-12T13:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse p4 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/529140#M149396</link>
      <description>&lt;P&gt;See if this helps.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... | rex "pid \d+ (?&amp;lt;user&amp;gt;\S+@\S+)"
| rex "lapse (?&amp;lt;lapse&amp;gt;\d+\.?\d+)"
| where lapse &amp;gt; 100
| table user lapse&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 12 Nov 2020 13:45:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/529140#M149396</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-12T13:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse p4 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/529149#M149400</link>
      <description>&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 14:28:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/529149#M149400</guid>
      <dc:creator>vinodarokiya</dc:creator>
      <dc:date>2020-11-12T14:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse p4 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/529256#M149445</link>
      <description>&lt;P&gt;May I please know how to extract one more table with all data that s there inside single quotes like :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;user-sizes&lt;/SPAN&gt; &lt;SPAN class="t"&gt;//ddc/...&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After getting username , lapse ,how do we even print data that s within single quotes &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 08:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/529256#M149445</guid>
      <dc:creator>vinodarokiya</dc:creator>
      <dc:date>2020-11-13T08:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse p4 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/529307#M149474</link>
      <description>&lt;P&gt;The process is very similar&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... | rex "'(?&amp;lt;field1&amp;gt;[^\/]+)\/(?&amp;lt;field2&amp;gt;[^\/]*)\/(?&amp;lt;field3&amp;gt;[^\/]+)\/(?&amp;lt;field4&amp;gt;[^']+)'"
...&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 13 Nov 2020 14:13:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/529307#M149474</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-13T14:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to parse p4 logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/530049#M149753</link>
      <description>Thank you!</description>
      <pubDate>Thu, 19 Nov 2020 08:37:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-parse-p4-logs/m-p/530049#M149753</guid>
      <dc:creator>vinodarokiya</dc:creator>
      <dc:date>2020-11-19T08:37:01Z</dc:date>
    </item>
  </channel>
</rss>

