Monitoring Splunk

CommonBaseEvent treatment

benji00
New Member

Hello all,

I receiving some event from our Monitoring Agent tool (from the editor Dassault Systemes) through Common Base Event format like:

  <extendedDataElements name="status" type="string">
    <values>0</values>
  </extendedDataElements>
  <extendedDataElements name="elapsed" type="string">
    <values>203</values>
  </extendedDataElements>
  <extendedDataElements name="_period" type="string">
    <values>300</values>
  </extendedDataElements>
  <extendedDataElements name="connection" type="string">
    <values>47</values>
  </extendedDataElements>
  <extendedDataElements name="logoutTime" type="string">
    <values>62</values>
  </extendedDataElements>
  <extendedDataElements name="getLoginPageTime" type="string">
    <values>78</values>
  </extendedDataElements>
  <sourceComponentId componentType="ProductName" instanceId="3dpassport_TEST1" component="serviceHealthCheck" processId="" locationType="Hostname" location="io-ws-3de71ts" subComponent="" componentIdType="ProductName"/>
  <situation categoryName="ReportSituation">
    <situationType reportCategory="LOG" xsi:type="ReportSituation" reasoningScope="INTERNAL"/>
  </situation>
</CommonBaseEvent>

I don't really understand how can I operate for example the "ELAPSED" extended elements and moreover be able to track his value evolution
Any clue on your side?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...