Monitoring Splunk

I need to extract the event with INFO log and below highlighted string in field name cronjob

Hemant1
Explorer

INFO [monki_HMCatalogSyncJob::de.hybris.platform.servicelayer.internal.jalo.ServicelayerJob] -[J= U= C=] (monki) (0000VVDK) [CatalogVersionSyncJob] Finished synchronization in 0d 00h:01m:33s:630ms. No errors.

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| rex "INFO \[(?<cronjob>.+)::"

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex "INFO \[(?<cronjob>.+)::"
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...

Starting With Observability: OpenTelemetry Best Practices

Tech Talk Starting With Observability: OpenTelemetry Best Practices Tuesday, October 17, 2023   |  11AM PST / ...