<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk extraction help! in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696735#M236792</link>
    <description>&lt;P&gt;Hi&amp;nbsp; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp; How do i get the difference of the time stamp? . I want the difference of starting timestamp and the completed time stamp&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;"My base query"  | rex "status:\s+(?&amp;lt;Status&amp;gt;.*)\"}" | rex field=_raw "\((?&amp;lt;Message_Id&amp;gt;[^\)]*)" | rex "Path\:\s+(?&amp;lt;ResourcePath&amp;gt;.*)\"" | eval timestamp_s = timestamp/1000 | eval human_readable_time = strftime(timestamp_s, "%Y-%m-%d %H:%M:%S") | transaction Message_Id startswith="Starting execution for request" endswith="Successfully completed execution"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RAW_LOG&lt;/P&gt;
&lt;DIV&gt;
&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;8/19/24&lt;/P&gt;
&lt;P&gt;9:56:05.113 AM&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;{"id":"38448254623555555", "timestamp":1724079365113, "message":"(fghhhhhh-244933333-456789-rrrrrrrrrr) Startingexecutionforrequest:f34444-22222-44444-999999-0888888"}&lt;/P&gt;
&lt;P&gt;{"id":"38448254444444444", "timestamp":1724079365126, "message":"(fghhhhhh-244933333-456789-rrrrrrrrrr) Methodcompletedwithstatus:200"}&lt;/P&gt;
&lt;P&gt;{"id":"38448222222222222", "timestamp":1724079365126, "message":"(fghhhhhh-244933333-456789-rrrrrrrrrr) Successfullycompletedexecution"}&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN&gt;id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;38417111111111111&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN&gt;timestamp&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;:1724079365126&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN&gt;message&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"(&lt;/SPAN&gt;&lt;SPAN&gt;fghhhhhh-244933333-456789-rrrrrrrrrr&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN&gt;AWS Integration Endpoint RequestId :f32222-22222-44444-999999-0888888&lt;/SPAN&gt;&lt;SPAN&gt;"}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kc_prane_0-1724080713844.png" style="width: 717px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32294i8BB5C75B7C9F3604/image-dimensions/717x65?v=v2" width="717" height="65" role="button" title="kc_prane_0-1724080713844.png" alt="kc_prane_0-1724080713844.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 19 Aug 2024 15:55:51 GMT</pubDate>
    <dc:creator>kc_prane</dc:creator>
    <dc:date>2024-08-19T15:55:51Z</dc:date>
    <item>
      <title>Splunk extraction help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696542#M236723</link>
      <description>&lt;P&gt;Hello , I have a transaction which is coming as multievent. i can use the&amp;nbsp;&amp;nbsp;"| transaction" command to club as one event.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; I want the transaction ID extracted&amp;nbsp; based on the below-highlighted ( Green)&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Now, I want to&amp;nbsp; get the transaction time&amp;nbsp; based on the below-highlighted&amp;nbsp; (Yellow)&lt;/P&gt;&lt;P&gt;Below is the raw event log.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kc_prane_0-1723838182430.png" style="width: 592px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32271i42DF13211C22EA5B/image-dimensions/592x135?v=v2" width="592" height="135" role="button" title="kc_prane_0-1723838182430.png" alt="kc_prane_0-1723838182430.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks In advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 19:56:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696542#M236723</guid>
      <dc:creator>kc_prane</dc:creator>
      <dc:date>2024-08-16T19:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk extraction help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696544#M236724</link>
      <description>&lt;P&gt;Which (if any) fields do you already have extracted?&lt;/P&gt;&lt;P&gt;Are the transaction ids unique i.e will there be only one "Starting ..." message and one "Successfully completed" message per transaction id?&lt;/P&gt;&lt;P&gt;Please can you share text versions of your events rather than pictures as they are easier to deal with when simulating a solution.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 20:02:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696544#M236724</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-16T20:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk extraction help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696545#M236725</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;@&lt;A class="" href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168" target="_self"&gt;&lt;SPAN class=""&gt;ITWhisperer&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; Thanks for your response. I had not extracted any yet cause the logs are not yet in splunk but will be soon&amp;nbsp; Yes, the transaction ID are unique.&amp;nbsp; The below is what i got from cloud watch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2024-08-12T10:04:16.962-04:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (434-abc-345789-de456ght) Extended Request Id: cmtf1111111111111111=&lt;/P&gt;&lt;P&gt;2024-08-12T10:04:16.963-04:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (434-abc-345789-de456ght) Verifying Usage Plan for request: AAAAAAAAAAAAAAAAAAAAAAAA&lt;/P&gt;&lt;P&gt;2024-08-12T10:04:16.964-04:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (434-abc-345789-de456ght)&amp;nbsp; BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB&lt;/P&gt;&lt;P&gt;2024-08-12T10:04:16.964-04:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (434-abc-345789-de456ght) AAAAAAAAAABBBBBBBBBBBBBCCCCCCCCCCCCCCCCCC&lt;/P&gt;&lt;P&gt;2024-08-12T10:04:16.964-04:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (434-abc-345789-de456ght) Starting execution for request: 8hhhhh-cdcd-434444-8bbb-dedr44444&lt;/P&gt;&lt;P&gt;2024-08-16T10:04:16.964-04:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (434-abc-345789-de456ght) HTTP Method: POST, Resource Path: /ddd/Verifyffghhjj/ddddddd&lt;/P&gt;&lt;P&gt;2024-08-16T10:04:25.969-04:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (434-abc-345789-de456ght) Successfully completed execution&lt;/P&gt;&lt;P&gt;2024-08-16T10:04:25.969-04:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (434-abc-345789-de456ght) Method completed with status: 200&lt;/P&gt;&lt;P&gt;2024-08-16T10:04:25.969-04:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (434-abc-345789-de456ght)&amp;nbsp; AAAAAA Integration Endpoint RequestId: 11111111111111111111&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 20:10:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696545#M236725</guid>
      <dc:creator>kc_prane</dc:creator>
      <dc:date>2024-08-16T20:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk extraction help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696557#M236732</link>
      <description>&lt;P&gt;Do you mean something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "^\S+\s+\((?&amp;lt;transaction_id&amp;gt;[^\)]+)"
| transaction transaction_id startswith="Starting execution for request" endswith="Successfully completed execution"&lt;/LI-CODE&gt;&lt;P&gt;Here is an emulation of your mock sample data you can play with and compare with real data&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults format=csv data="_raw
2024-08-12T10:04:16.962-04:00          (434-abc-345789-de456ght) Extended Request Id: cmtf1111111111111111=
2024-08-12T10:04:16.963-04:00          (434-abc-345789-de456ght) Verifying Usage Plan for request: AAAAAAAAAAAAAAAAAAAAAAAA
2024-08-12T10:04:16.964-04:00          (434-abc-345789-de456ght)  BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
2024-08-12T10:04:16.964-04:00          (434-abc-345789-de456ght) AAAAAAAAAABBBBBBBBBBBBBCCCCCCCCCCCCCCCCCC
2024-08-12T10:04:16.964-04:00          (434-abc-345789-de456ght) Starting execution for request: 8hhhhh-cdcd-434444-8bbb-dedr44444
2024-08-16T10:04:16.964-04:00          (434-abc-345789-de456ght) HTTP Method: POST, Resource Path: /ddd/Verifyffghhjj/ddddddd
2024-08-16T10:04:25.969-04:00          (434-abc-345789-de456ght) Successfully completed execution
2024-08-16T10:04:25.969-04:00          (434-abc-345789-de456ght) Method completed with status: 200
2024-08-16T10:04:25.969-04:00          (434-abc-345789-de456ght)  AAAAAA Integration Endpoint RequestId: 11111111111111111111"
| rex "^(?&amp;lt;_time&amp;gt;\S+)"
| eval _time = strptime(_time, "%FT%T.%3N")
| sort - _time
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 06:22:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696557#M236732</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-08-17T06:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk extraction help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696735#M236792</link>
      <description>&lt;P&gt;Hi&amp;nbsp; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp; How do i get the difference of the time stamp? . I want the difference of starting timestamp and the completed time stamp&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;"My base query"  | rex "status:\s+(?&amp;lt;Status&amp;gt;.*)\"}" | rex field=_raw "\((?&amp;lt;Message_Id&amp;gt;[^\)]*)" | rex "Path\:\s+(?&amp;lt;ResourcePath&amp;gt;.*)\"" | eval timestamp_s = timestamp/1000 | eval human_readable_time = strftime(timestamp_s, "%Y-%m-%d %H:%M:%S") | transaction Message_Id startswith="Starting execution for request" endswith="Successfully completed execution"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RAW_LOG&lt;/P&gt;
&lt;DIV&gt;
&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;8/19/24&lt;/P&gt;
&lt;P&gt;9:56:05.113 AM&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;{"id":"38448254623555555", "timestamp":1724079365113, "message":"(fghhhhhh-244933333-456789-rrrrrrrrrr) Startingexecutionforrequest:f34444-22222-44444-999999-0888888"}&lt;/P&gt;
&lt;P&gt;{"id":"38448254444444444", "timestamp":1724079365126, "message":"(fghhhhhh-244933333-456789-rrrrrrrrrr) Methodcompletedwithstatus:200"}&lt;/P&gt;
&lt;P&gt;{"id":"38448222222222222", "timestamp":1724079365126, "message":"(fghhhhhh-244933333-456789-rrrrrrrrrr) Successfullycompletedexecution"}&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN&gt;id&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;38417111111111111&lt;/SPAN&gt;&lt;SPAN&gt;", "&lt;/SPAN&gt;&lt;SPAN&gt;timestamp&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;:1724079365126&lt;/SPAN&gt;&lt;SPAN&gt;, "&lt;/SPAN&gt;&lt;SPAN&gt;message&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"(&lt;/SPAN&gt;&lt;SPAN&gt;fghhhhhh-244933333-456789-rrrrrrrrrr&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN&gt;AWS Integration Endpoint RequestId :f32222-22222-44444-999999-0888888&lt;/SPAN&gt;&lt;SPAN&gt;"}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kc_prane_0-1724080713844.png" style="width: 717px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32294i8BB5C75B7C9F3604/image-dimensions/717x65?v=v2" width="717" height="65" role="button" title="kc_prane_0-1724080713844.png" alt="kc_prane_0-1724080713844.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 19 Aug 2024 15:55:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696735#M236792</guid>
      <dc:creator>kc_prane</dc:creator>
      <dc:date>2024-08-19T15:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk extraction help!</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696761#M236799</link>
      <description>&lt;P&gt;The transaction command provides a duration field for the difference in times. Is this not sufficient for your needs?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 17:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-extraction-help/m-p/696761#M236799</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-19T17:02:18Z</dc:date>
    </item>
  </channel>
</rss>

