Dashboards & Visualizations

How to fetch the time from the logs

aditsss
Motivator

Hi All,

I have below two logs:

First Log

2023-09-05 00:17:56.987 [INFO ] [pool-3-thread-1] ReadControlFileImpl - Reading Control-File /absin/CARS.HIERCTR.D090423.T001603

Second Log

2023-09-05 03:55:15.808 [INFO ] [Thread-20] FileEventCreator - Completed Settlement file processing, CARS.HIER.D090423.T001603 records processed: 161094

I want to capture the trimmings for both logs:

My current queries

index="abc"sourcetype =600000304_gg_abs_ipc2 source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "Reading Control-File /absin/CARS.HIERCTR."

index="abc"sourcetype =600000304_gg_abs_ipc2 source="/amex/app/gfp-settlement-raw/logs/gfp-settlement-raw.log" "Completed Settlement file processing, CARS.HIER."

Labels (3)
0 Karma

andrew_nelson
Communicator

Splunk should automatically be capturing that time into the _time field. 

If you still need to extract it into a field though, try : 

| rex field=_raw "^(?<time_field>[^\s]+)\s"

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try looking to see if it has already been extracted - this is usually in a field called _time

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...