<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: calculate send response duration in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573332#M199805</link>
    <description>&lt;P&gt;Most of this is fabricating data.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval temp="2021-07-15 00:00:01,800 INFO CUST.InAB-ServerApp-1234567 [MyService] Packet Processed: A[50] B[0000211]
2021-07-15 00:00:01,893 INFO ABCD.DaQW-ParityGQQ-1231234 [MyService] Packet Processed: A[60] B[0000465]
2021-07-15 00:00:01,894 INFO MNBV.ZaQW-ChatCXZ-1478523 [MyService] Packet Processed: A[70] B[0000369]
2021-07-15 00:00:11,719 INFO CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567 [MyService] Normal Packet Received: A[55] B[0000211]
2021-07-15 00:00:11,720 INFO EFGH.GaXZ-Carry2-3456789_ABCD.DaQW-ParityGQQ-1231234 [MyService] Normal Packet Received: A[65] B[0000456]
" 
| makemv tokenizer="(.*)\n" temp 
| mvexpand temp 
| rex field=temp "^(?&amp;lt;timestamp&amp;gt;.{23}) INFO (?&amp;lt;customer&amp;gt;.*) \[MyService\] (?&amp;lt;status&amp;gt;.*): (?&amp;lt;Acode&amp;gt;.*) (?&amp;lt;Bcode&amp;gt;.*)" 
| fields - temp 
| rex field=customer "_(?&amp;lt;customer2&amp;gt;.*)" 
| eval customer=coalesce(customer2,customer) 
| fields - customer2 
| eval startTime=if(status="Packet Processed",strptime(timestamp,"%Y-%m-%d %H:%M:%S,%3Q"),null()) 
| eval endTime=if(status="Normal Packet Received",strptime(timestamp,"%Y-%m-%d %H:%M:%S,%3Q"),null()) 
| stats values(startTime) as startTime, values(endTime) as endTime by customer 
| eval status=endTime-startTime 
| fields - startTime, endTime 
| fillnull value="no receive" status&lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 02 Nov 2021 15:29:34 GMT</pubDate>
    <dc:creator>tread_splunk</dc:creator>
    <dc:date>2021-11-02T15:29:34Z</dc:date>
    <item>
      <title>calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573273#M199793</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have log like below need to extract "&lt;STRONG&gt;Send&amp;amp;Receive duration&lt;/STRONG&gt;" and "&lt;STRONG&gt;send that has&lt;/STRONG&gt; &lt;STRONG&gt;not respond".&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;this is send&lt;/STRONG&gt;&lt;BR /&gt;2021-07-15 00:00:01,800 INFO CUST.InAB-ServerApp-&lt;FONT color="#008000"&gt;1234567&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Packet Processed: A[&lt;STRONG&gt;50&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000211&lt;/STRONG&gt;]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;this is send&lt;/STRONG&gt;&lt;BR /&gt;2021-07-15 00:00:01,893 INFO ABCD.DaQW-ParityGQQ-&lt;FONT color="#008000"&gt;1231234&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Packet Processed: A[&lt;STRONG&gt;60&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000465&lt;/STRONG&gt;]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;this is send&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2021-07-15 00:00:01,894 INFO MNBV.ZaQW-ChatCXZ-&lt;FONT color="#008000"&gt;1478523&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Packet Processed: A[&lt;STRONG&gt;70&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000369&lt;/STRONG&gt;]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;this is recieve&lt;/STRONG&gt;&lt;BR /&gt;2021-07-15 00:00:11,719 INFO CUST.VqPO-Oracle7-&lt;FONT color="#FF0000"&gt;9876543&lt;/FONT&gt;_CUST.InAB-ServerApp-&lt;FONT color="#008000"&gt;1234567&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Normal Packet Received: A[&lt;STRONG&gt;55&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000211&lt;/STRONG&gt;]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;this is recieve&lt;/STRONG&gt;&lt;BR /&gt;2021-07-15 00:00:11,720 INFO EFGH.GaXZ-Carry2-&lt;FONT color="#FF0000"&gt;3456789&lt;/FONT&gt;_ABCD.DaQW-ParityGQQ-&lt;FONT color="#008000"&gt;1231234&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Normal Packet Received: A[&lt;STRONG&gt;65&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000456&lt;/STRONG&gt;]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is what happen:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;step1&lt;/STRONG&gt;: find send&amp;nbsp;id&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;CUST.InAB-ServerApp-1234567&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;ABCD.DaQW-ParityGQQ-1231234&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;MNBV.ZaQW-ChatCXZ-1478523&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;step2:&lt;/STRONG&gt; find response id&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;EFGH.GaXZ-Carry2-3456789_ABCD.DaQW-ParityGQQ-1231234&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;FYI: related events structure like this:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#800000"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Send:&lt;/STRONG&gt; &lt;/FONT&gt;CUST.InAB-ServerApp-1234567&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#008000"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Recieve:&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;CUST.VqPO-Oracle7-9876543_&lt;FONT color="#993300"&gt;CUST.InAB-ServerApp-1234567&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;step3:&lt;/STRONG&gt; check this condition&amp;nbsp; &lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#008000"&gt;&lt;FONT color="#000000"&gt;A+5 AND B=B to match related send receive.&lt;BR /&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;2021-07-15 00:00:01,800 INFO &lt;FONT color="#339966"&gt;CUST.InAB-ServerApp-1234567&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Packet Processed: &lt;FONT color="#FF00FF"&gt;A[&lt;STRONG&gt;50&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000211&lt;/STRONG&gt;]&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;2021-07-15 00:00:11,719 INFO&lt;FONT color="#339966"&gt; CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Normal Packet Received:&lt;FONT color="#FF00FF"&gt; A[&lt;STRONG&gt;55&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000211&lt;/STRONG&gt;]&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;step4:&lt;/STRONG&gt; finally show id that not have&amp;nbsp;&lt;FONT color="#000000"&gt;receive, and duration of each send&amp;amp;receive&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;expected Output:&lt;P&gt;id&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; status&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;MNBV.ZaQW-ChatCXZ-1478523&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; no receive&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9,919&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;EFGH.GaXZ-Carry2-3456789_ABCD.DaQW-ParityGQQ-&lt;/FONT&gt;&lt;FONT color="#008000"&gt;&lt;FONT color="#000000"&gt;1231234&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9,826&lt;/FONT&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Any idea?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 02 Nov 2021 08:20:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573273#M199793</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2021-11-02T08:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573332#M199805</link>
      <description>&lt;P&gt;Most of this is fabricating data.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval temp="2021-07-15 00:00:01,800 INFO CUST.InAB-ServerApp-1234567 [MyService] Packet Processed: A[50] B[0000211]
2021-07-15 00:00:01,893 INFO ABCD.DaQW-ParityGQQ-1231234 [MyService] Packet Processed: A[60] B[0000465]
2021-07-15 00:00:01,894 INFO MNBV.ZaQW-ChatCXZ-1478523 [MyService] Packet Processed: A[70] B[0000369]
2021-07-15 00:00:11,719 INFO CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567 [MyService] Normal Packet Received: A[55] B[0000211]
2021-07-15 00:00:11,720 INFO EFGH.GaXZ-Carry2-3456789_ABCD.DaQW-ParityGQQ-1231234 [MyService] Normal Packet Received: A[65] B[0000456]
" 
| makemv tokenizer="(.*)\n" temp 
| mvexpand temp 
| rex field=temp "^(?&amp;lt;timestamp&amp;gt;.{23}) INFO (?&amp;lt;customer&amp;gt;.*) \[MyService\] (?&amp;lt;status&amp;gt;.*): (?&amp;lt;Acode&amp;gt;.*) (?&amp;lt;Bcode&amp;gt;.*)" 
| fields - temp 
| rex field=customer "_(?&amp;lt;customer2&amp;gt;.*)" 
| eval customer=coalesce(customer2,customer) 
| fields - customer2 
| eval startTime=if(status="Packet Processed",strptime(timestamp,"%Y-%m-%d %H:%M:%S,%3Q"),null()) 
| eval endTime=if(status="Normal Packet Received",strptime(timestamp,"%Y-%m-%d %H:%M:%S,%3Q"),null()) 
| stats values(startTime) as startTime, values(endTime) as endTime by customer 
| eval status=endTime-startTime 
| fields - startTime, endTime 
| fillnull value="no receive" status&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 02 Nov 2021 15:29:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573332#M199805</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-11-02T15:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573337#M199806</link>
      <description>&lt;P&gt;Thanks for answer,&lt;/P&gt;&lt;P&gt;here is the output:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;FONT color="#000000"&gt;MNBV.ZaQW-ChatCXZ-1478523&lt;/FONT&gt;&lt;/TD&gt;&lt;TD&gt;9.827000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;CUST.InAB-ServerApp-1234567&lt;/TD&gt;&lt;TD&gt;9.919000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;MNBV.ZaQW-ChatCXZ-1478523&lt;/TD&gt;&lt;TD&gt;no receive&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the expected output:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="256.1875px" height="25px"&gt;&lt;SPAN&gt;MNBV.ZaQW-ChatCXZ-1478523&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="85.546875px" height="25px"&gt;no receive&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="256.1875px" height="25px"&gt;&lt;FONT color="#000000"&gt;CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="85.546875px" height="25px"&gt;&lt;FONT color="#000000"&gt;9,919&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="256.1875px" height="25px"&gt;&lt;FONT color="#000000"&gt;EFGH.GaXZ-Carry2-3456789_ABCD.DaQW-ParityGQQ-&lt;/FONT&gt;&lt;FONT color="#008000"&gt;&lt;FONT color="#000000"&gt;&lt;A href="tel:1231234" target="_blank" rel="noopener"&gt;1231234&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="85.546875px" height="25px"&gt;&lt;FONT color="#008000"&gt;&lt;FONT color="#000000"&gt;9,826&lt;/FONT&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI:step3 missed, not check condition.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 12:01:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573337#M199806</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2021-11-04T12:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573386#M199819</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217339"&gt;@indeed_2000&lt;/a&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval temp="2021-07-15 00:00:01,800 INFO CUST.InAB-ServerApp-1234567 [MyService] Packet Processed: A[50] B[0000211]
2021-07-15 00:00:01,893 INFO ABCD.DaQW-ParityGQQ-1231234 [MyService] Packet Processed: A[60] B[0000465]
2021-07-15 00:00:01,894 INFO MNBV.ZaQW-ChatCXZ-1478523 [MyService] Packet Processed: A[70] B[0000369]
2021-07-15 00:00:11,719 INFO CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567 [MyService] Normal Packet Received: A[55] B[0000211]
2021-07-15 00:00:11,720 INFO EFGH.GaXZ-Carry2-3456789_ABCD.DaQW-ParityGQQ-1231234 [MyService] Normal Packet Received: A[65] B[0000465]
" 
| makemv tokenizer="(.*)\n" temp 
| mvexpand temp 
| rex field=temp "^(?&amp;lt;timestamp&amp;gt;.{23}) INFO (?&amp;lt;customer&amp;gt;.*) \[MyService\] (?&amp;lt;status&amp;gt;.*): A\[(?&amp;lt;Acode&amp;gt;.*)\] B\[(?&amp;lt;Bcode&amp;gt;.*)\]" 
| fields - temp 
| rex field=customer "_(?&amp;lt;customer2&amp;gt;.*)" 
| eval customer2=coalesce(customer2,customer), customer=if(customer=customer2,null(),customer) 
| eval startTime=if(status="Packet Processed",strptime(timestamp,"%Y-%m-%d %H:%M:%S,%3Q"),null()), endTime=if(status="Normal Packet Received",strptime(timestamp,"%Y-%m-%d %H:%M:%S,%3Q"),null()) 
| eval AcodeStart=if(status="Packet Processed",Acode,null()),BcodeStart=if(status="Packet Processed",Bcode,null()),AcodeFinish=if(status="Normal Packet Received",Acode,null()),BcodeFinish=if(status="Normal Packet Received",Bcode,null()) 
| fields - Acode Bcode _time timestamp status 
| stats values(*) as * by customer2 
| eval status=endTime-startTime , customer=coalesce(customer,customer2) 
| fields - startTime, endTime 
| fillnull value="no receive" status 
| where isnull(AcodeFinish) OR (AcodeFinish=AcodeStart+5 AND BcodeStart=BcodeFinish) 
| table customer status&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 02 Nov 2021 20:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573386#M199819</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-11-02T20:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573465#M199840</link>
      <description>&lt;P&gt;I try it on small part of log it work perfect but on a large scale I have issue.&lt;/P&gt;&lt;P&gt;here is the line that cause of issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;actually duration between green lines show on table.&amp;nbsp;&lt;/P&gt;&lt;P&gt;red lines show there is no "receive", because not have second line with condition that I mention A=A+5 AND B=B&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;---------------------------------------&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;this is recieve&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;2021-07-15 00:00:01,800 INFO CUST.InAB-ServerApp-1234567&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Normal Packet Received: A[&lt;STRONG&gt;50&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000211&lt;/STRONG&gt;]&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;this is send&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;2021-07-15 00:00:01,800 INFO CUST.InAB-ServerApp-1234567&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Packet Processed: A[&lt;STRONG&gt;50&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000211&lt;/STRONG&gt;]&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;this is recieve&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;2021-07-15 00:00:11,719 INFO CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Normal Packet Received: A[&lt;STRONG&gt;55&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000211&lt;/STRONG&gt;]&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;this is send&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;2021-07-15 00:00:11,719 INFO CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Packet Processed: A[&lt;STRONG&gt;55&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000211&lt;/STRONG&gt;]&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;----------------------------------------&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;this is &lt;SPAN&gt;recieve&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;2021-07-15 00:00:01,894 INFO MNBV.ZaQW-ChatCXZ-1478523&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Normal Packet Received: A[&lt;STRONG&gt;70&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000369&lt;/STRONG&gt;]&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;this is send&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;2021-07-15 00:00:01,894 INFO MNBV.ZaQW-ChatCXZ-1478523&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[MyService] Packet Processed: A[&lt;STRONG&gt;70&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000369&lt;/STRONG&gt;]&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;----------------------------------------&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;this is recieve&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-07-15 00:00:01,893 INFO ABCD.DaQW-ParityGQQ-&lt;/SPAN&gt;1231234&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;[MyService] Normal Packet Received: A[&lt;/SPAN&gt;&lt;STRONG&gt;60&lt;/STRONG&gt;&lt;SPAN&gt;] B[&lt;/SPAN&gt;&lt;STRONG&gt;0000465&lt;/STRONG&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;SPAN&gt;&lt;STRONG&gt;this is send&lt;/STRONG&gt;&lt;BR /&gt;2021-07-15 00:00:01,893 INFO ABCD.DaQW-ParityGQQ-1231234&amp;nbsp;[MyService] Packet Processed: A[&lt;STRONG&gt;60&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000465&lt;/STRONG&gt;]&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;SPAN&gt;&lt;STRONG&gt;this is recieve&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;SPAN&gt;2021-07-15 00:00:11,720 INFO EFGH.GaXZ-Carry2-3456789_ABCD.DaQW-ParityGQQ-1231234&amp;nbsp;[MyService] Normal Packet Received: A[&lt;STRONG&gt;65&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000465&lt;/STRONG&gt;]&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;STRONG&gt;this is send&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-07-15 00:00:11,720 INFO EFGH.GaXZ-Carry2-3456789_ABCD.DaQW-ParityGQQ-1231234&amp;nbsp;[MyService] Packet Processed: A[&lt;STRONG&gt;65&lt;/STRONG&gt;] B[&lt;STRONG&gt;0000465&lt;/STRONG&gt;]&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the expected output:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="256.1875px" height="25px"&gt;&lt;SPAN&gt;MNBV.ZaQW-ChatCXZ-1478523&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="85.546875px" height="25px"&gt;no receive&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="256.1875px" height="69px"&gt;&lt;FONT color="#000000"&gt;CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="85.546875px" height="69px"&gt;&lt;FONT color="#000000"&gt;9,919&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="256.1875px" height="69px"&gt;&lt;FONT color="#000000"&gt;EFGH.GaXZ-Carry2-3456789_ABCD.DaQW-ParityGQQ-&lt;/FONT&gt;&lt;FONT color="#008000"&gt;&lt;FONT color="#000000"&gt;&lt;A href="tel:1231234" target="_blank" rel="noopener nofollow noreferrer"&gt;1231234&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="85.546875px" height="69px"&gt;&lt;FONT color="#008000"&gt;&lt;FONT color="#000000"&gt;9,826&lt;/FONT&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 12:00:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573465#M199840</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2021-11-04T12:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573479#M199845</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217339"&gt;@indeed_2000&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your second green pair have different B codes. 465 vs 456.&amp;nbsp; This is a typo, correct?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 13:47:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573479#M199845</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-11-03T13:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573482#M199846</link>
      <description>&lt;P&gt;you right, it is a typo, I've edit it.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 13:52:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573482#M199846</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2021-11-03T13:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573600#M199889</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217339"&gt;@indeed_2000&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is ...&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="256.1875px" height="25px"&gt;ABCD.DaQW-ParityGQQ-1231234&lt;/TD&gt;&lt;TD width="85.546875px" height="25px"&gt;no receive&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...in the output?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 09:38:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573600#M199889</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-11-04T09:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573603#M199891</link>
      <description>&lt;P&gt;For more clarification Here is flow:&lt;/P&gt;&lt;P&gt;1-receive &lt;STRONG&gt;request&lt;/STRONG&gt; from a source&lt;/P&gt;&lt;P&gt;2-processed&amp;nbsp;&lt;STRONG&gt;request&lt;/STRONG&gt;&amp;nbsp;and send to another node&lt;/P&gt;&lt;P&gt;3-receive &lt;STRONG&gt;response&lt;/STRONG&gt; from that node&lt;/P&gt;&lt;P&gt;4-send &lt;STRONG&gt;response&lt;/STRONG&gt; to source&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Need to extract duration between step 2 and 3&lt;/P&gt;&lt;P&gt;sometimes &amp;nbsp;node doesn’t send response, then step 3,4 missed and flow is incomplete.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI: you may confused with step 1,2 or 3,4 (send and receive) keyword, but in simple way 1,2 means request received and send to node. 3,4 means receive response and send to source.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 09:59:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573603#M199891</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2021-11-04T09:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573611#M199895</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217339"&gt;@indeed_2000&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still not sure why...&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="256.1875px" height="25px"&gt;ABCD.DaQW-ParityGQQ-1231234&lt;/TD&gt;&lt;TD width="85.546875px" height="25px"&gt;&lt;P&gt;no receive&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...is in the result.&amp;nbsp; Shouldn't it be the red one? i.e...&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-07-15 00:00:01,894 INFO MNBV.ZaQW-ChatCXZ-1478523&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;[MyService] Packet Processed: A[&lt;/SPAN&gt;&lt;STRONG&gt;70&lt;/STRONG&gt;&lt;SPAN&gt;] B[&lt;/SPAN&gt;&lt;STRONG&gt;0000369&lt;/STRONG&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 11:20:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573611#M199895</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-11-04T11:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573613#M199897</link>
      <description>&lt;P&gt;Sorry it’s typo, &amp;nbsp;modify that too.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 11:59:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573613#M199897</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2021-11-04T11:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: calculate send response duration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573622#M199901</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217339"&gt;@indeed_2000&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its not very pretty.&amp;nbsp; And requires extensive testing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval temp="2021-07-15 00:00:01,800 INFO CUST.InAB-ServerApp-1234567 [MyService] Normal Packet Received: A[50] B[0000211]
2021-07-15 00:00:01,800 INFO CUST.InAB-ServerApp-1234567 [MyService] Packet Processed: A[50] B[0000211]
2021-07-15 00:00:11,719 INFO CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567 [MyService] Normal Packet Received: A[55] B[0000211]
2021-07-15 00:00:11,719 INFO CUST.VqPO-Oracle7-9876543_CUST.InAB-ServerApp-1234567 [MyService] Packet Processed: A[55] B[0000211]
2021-07-15 00:00:01,894 INFO MNBV.ZaQW-ChatCXZ-1478523 [MyService] Normal Packet Received: A[70] B[0000369]
2021-07-15 00:00:01,894 INFO MNBV.ZaQW-ChatCXZ-1478523 [MyService] Packet Processed: A[70] B[0000369]
2021-07-15 00:00:01,893 INFO ABCD.DaQW-ParityGQQ-1231234 [MyService] Normal Packet Received: A[60] B[0000465]
2021-07-15 00:00:01,893 INFO ABCD.DaQW-ParityGQQ-1231234 [MyService] Packet Processed: A[60] B[0000456]
2021-07-15 00:00:11,720 INFO EFGH.GaXZ-Carry2-3456789_ABCD.DaQW-ParityGQQ-1231234 [MyService] Normal Packet Received: A[65] B[0000456]
2021-07-15 00:00:11,720 INFO EFGH.GaXZ-Carry2-3456789_ABCD.DaQW-ParityGQQ-1231234 [MyService] Packet Processed: A[65] B[0000456]
"
| makemv tokenizer="(.*)\n" temp
| mvexpand temp
| rex field=temp "^(?&amp;lt;timestamp&amp;gt;.{23}) INFO (?&amp;lt;customer&amp;gt;.*) \[MyService\] (?&amp;lt;status&amp;gt;.*): A\[(?&amp;lt;Acode&amp;gt;.*)\] B\[(?&amp;lt;Bcode&amp;gt;.*)\]"
| fields - temp
| rex field=customer "_(?&amp;lt;customer2&amp;gt;.*)"
| eval customer2=coalesce(customer2,customer), customer=if(customer=customer2,null(),customer)
| eval sendTime=if(status="Packet Processed",strptime(timestamp,"%Y-%m-%d %H:%M:%S,%3Q"),null()), receiveTime=if(status="Normal Packet Received",strptime(timestamp,"%Y-%m-%d %H:%M:%S,%3Q"),null())
| eval AcodeSend=if(status="Packet Processed",Acode,null()),BcodeSend=if(status="Packet Processed",Bcode,null()),AcodeReceive=if(status="Normal Packet Received",Acode,null()),BcodeReceive=if(status="Normal Packet Received",Bcode,null())
| eval AcodeReceiveLookFor=AcodeSend+5,acr=coalesce(AcodeReceive,AcodeReceiveLookFor)
| fields - Acode _time timestamp status AcodeReceiveLookFor
| stats values(*) as *,count by customer2,acr,Bcode
| eval duration=receiveTime-sendTime , customer=coalesce(customer,customer2)
| eval status=case(isnull(AcodeSend),"No Send",isnull(AcodeReceive),"No receive")
| eventstats max(duration) as duration by customer2
| where count=2 OR (status="No receive" AND isnull(duration))
| eval status=coalesce(status,duration)
| table customer status&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 04 Nov 2021 13:46:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/calculate-send-response-duration/m-p/573622#M199901</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-11-04T13:46:30Z</dc:date>
    </item>
  </channel>
</rss>

