<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to calculate duration inside a LDAP transaction for different LDAP operations in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-duration-inside-a-LDAP-transaction-for/m-p/69000#M180510</link>
    <description>&lt;P&gt;Many Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 20 Sep 2013 12:45:04 GMT</pubDate>
    <dc:creator>sgoyal</dc:creator>
    <dc:date>2013-09-20T12:45:04Z</dc:date>
    <item>
      <title>How to calculate duration inside a LDAP transaction for different LDAP operations</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-duration-inside-a-LDAP-transaction-for/m-p/68998#M180508</link>
      <description>&lt;P&gt;An Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Sep 20 12:36:30 simxxx slapd_simxxx[14304]: conn=2045 fd=28 ACCEPT from IP=99.888.7.50:50716 (IP=0.0.0.0:636)
Sep 20 12:36:32 simxxx slapd_simxxx[14304]: conn=2045 fd=28 TLS established tls_ssf=128 ssf=128
Sep 20 12:36:31 simxxx slapd_simxxx[14304]: conn=2045 op=0 BIND dn="cn=gabel,ou=msst,o=muenchen,c=de" method=128
Sep 20 12:36:31 simxxx slapd_simxxx[14304]: conn=2045 op=0 BIND dn="cn=gabel,ou=mssgmt,o=muenchen,c=de" mech=SIMPLE ssf=0
Sep 20 12:36:32 simxxx slapd_simxxx[14304]: conn=2045 op=0 RESULT tag=97 err=0 text=
Sep 20 12:36:32 simxxx slapd_simxxx[14304]: conn=2045 op=1 ADD dn="cn=aatek,ou=aaaaahange,ou=Kess,o=aaa,c=de"
Sep 20 12:36:33 simxxx slapd_simxxx[14304]: conn=2045 op=1 RESULT tag=105 err=0 text=
Sep 20 12:36:34 simxxx slapd_simxxx[14304]: conn=2045 op=2 EXT oid=1.3.6.1.4.1.4203.1.11.1
Sep 20 12:36:34 simxxx slapd_simxxx[14304]: conn=2045 op=2 PASSMOD id="cn=aaatek,ou=dddd,ou=ken,o=dddn,c=de" new
Sep 20 12:36:34 simxxx slapd_simxxx[14304]: conn=2045 op=2 RESULT oid= err=0 text=
Sep 20 12:36:35 simxxx slapd_simxxx[14304]: conn=2045 op=3 SRCH base="cn=sssstek,ou=Psss,ou=Kess,o=sss,c=de" scope=0 deref=0 filter="(|(objectClass=inetOrgPerson))"
Sep 20 12:36:35 simxxx slapd_simxxx[14304]: conn=2045 op=3 SRCH attr=objectclass
Sep 20 12:36:36 simxxx slapd_simxxx[14304]: conn=2045 op=3 SEARCH RESULT tag=101 err=32 nentries=0 text=
Sep 20 12:36:36 simxxx slapd_simxxx[14304]: conn=2045 op=4 UNBIND
Sep 20 12:36:37 simxxx slapd_simxxx[14304]: conn=2045 fd=28 closed
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I want the result in a form of table&lt;/P&gt;

&lt;HR /&gt;

&lt;PRE&gt;&lt;CODE&gt;conn|op|delay|
--------------
2045|0| 00:00:01
    |1| 00:00:01
    |2| 00:00:00
    |3| 00:00:01
    |4| 00:00:00
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have declared several field extractions for the values Client_Domain which in this case is 99.888.7, also Bind_Op which is 0 and Search_Op which is 3 in this case. I have earlier written a Perl Script which could give me the desired values because I could store the value in Variables and while pattern matching in other lines, could give the value of the variable. &lt;BR /&gt;
This is not possible in Splunk.&lt;/P&gt;

&lt;P&gt;Can you help me out with this. Thanks to Splunk Community.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:49:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-duration-inside-a-LDAP-transaction-for/m-p/68998#M180508</guid>
      <dc:creator>sgoyal</dc:creator>
      <dc:date>2020-09-28T14:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate duration inside a LDAP transaction for different LDAP operations</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-duration-inside-a-LDAP-transaction-for/m-p/68999#M180509</link>
      <description>&lt;P&gt;Hi sgoyal, I could help you on that but you have to wait until monday....&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2013 12:42:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-duration-inside-a-LDAP-transaction-for/m-p/68999#M180509</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2013-09-20T12:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate duration inside a LDAP transaction for different LDAP operations</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-duration-inside-a-LDAP-transaction-for/m-p/69000#M180510</link>
      <description>&lt;P&gt;Many Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2013 12:45:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-duration-inside-a-LDAP-transaction-for/m-p/69000#M180510</guid>
      <dc:creator>sgoyal</dc:creator>
      <dc:date>2013-09-20T12:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate duration inside a LDAP transaction for different LDAP operations</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-duration-inside-a-LDAP-transaction-for/m-p/69001#M180511</link>
      <description>&lt;P&gt;Something along these lines?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=ldap | stats min(_time) as min_t max(_time) as max_t by conn, op | eval dur=tostring((max_t-min_t), "duration") | fields - min_t - max_t
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2013 13:57:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-duration-inside-a-LDAP-transaction-for/m-p/69001#M180511</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-09-20T13:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate duration inside a LDAP transaction for different LDAP operations</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-duration-inside-a-LDAP-transaction-for/m-p/69002#M180512</link>
      <description>&lt;P&gt;Hi sgoyal,&lt;/P&gt;

&lt;P&gt;in addition to /K answers consider to configure your LDAP server to log the etime for each operations. This way you will get exact run times for each operation in milliseconds.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2013 09:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-calculate-duration-inside-a-LDAP-transaction-for/m-p/69002#M180512</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2013-09-23T09:38:22Z</dc:date>
    </item>
  </channel>
</rss>

