Monitoring Splunk

CommonBaseEvent treatment

benji00
New Member

Hello all,

I receiving some event from our Monitoring Agent tool (from the editor Dassault Systemes) through Common Base Event format like:

  <extendedDataElements name="status" type="string">
    <values>0</values>
  </extendedDataElements>
  <extendedDataElements name="elapsed" type="string">
    <values>203</values>
  </extendedDataElements>
  <extendedDataElements name="_period" type="string">
    <values>300</values>
  </extendedDataElements>
  <extendedDataElements name="connection" type="string">
    <values>47</values>
  </extendedDataElements>
  <extendedDataElements name="logoutTime" type="string">
    <values>62</values>
  </extendedDataElements>
  <extendedDataElements name="getLoginPageTime" type="string">
    <values>78</values>
  </extendedDataElements>
  <sourceComponentId componentType="ProductName" instanceId="3dpassport_TEST1" component="serviceHealthCheck" processId="" locationType="Hostname" location="io-ws-3de71ts" subComponent="" componentIdType="ProductName"/>
  <situation categoryName="ReportSituation">
    <situationType reportCategory="LOG" xsi:type="ReportSituation" reasoningScope="INTERNAL"/>
  </situation>
</CommonBaseEvent>

I don't really understand how can I operate for example the "ELAPSED" extended elements and moreover be able to track his value evolution
Any clue on your side?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...