Hi @Leon88,
you have to use a regex to extract this field, something like this:
index=your_index
| rex "\<ResponseID\>(?<ResponseID>[^\<]*)"
| table _time ResponseID
that you can test at https://regex101.com/r/Sj8hDe/1
Ciao.
Giuseppe
Hi @Leon88,
you have to use a regex to extract this field, something like this:
index=your_index
| rex "\<ResponseID\>(?<ResponseID>[^\<]*)"
| table _time ResponseID
that you can test at https://regex101.com/r/Sj8hDe/1
Ciao.
Giuseppe
Hi @Leon88 ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉