how
4/2/24 5:57:10.000 AM | 02-APR-2024 05:57:10 * (CONNECT_DATA=(SID=cpdb11)(CID=(PROGRAM=perl)(HOST=a5071ue1plora04)(USER=oracle))) * (ADDRESS=(PROTOCOL=tcp)(HOST=172.18.76.29)(PORT=53100)) * establish * cpdb11 * 0 | |
4/2/24 5:57:10.000 AM | 2024-04-02T05:57:10.270270-04:00 | |
4/2/24 5:57:09.000 AM | 02-APR-2024 05:57:09 * service_update * cpdb11 * 0 | |
4/2/24 5:57:09.000 AM | 02-APR-2024 05:57:09 * service_update * cpdb11 * 0 | |
4/2/24 5:57:08.000 AM | TNS-12505: TNS:listener does not currently know of SID given in connect descriptor | |
4/2/24 5:57:08.000 AM | 02-APR-2024 05:57:08 * (CONNECT_DATA=(SID=pdb09)(CID=(PROGRAM=perl)(HOST=a5071ue1plora04)(USER=oracle))) * (ADDRESS=(PROTOCOL=tcp)(HOST=172.18.76.29)(PORT=53098)) * establish * pdb09 * 12505 | |
4/2/24 5:57:08.000 AM | TNS-12505: TNS:listener does not currently know of SID given in connect descriptor | |
4/2/24 5:57:08.000 AM | 02-APR-2024 05:57:08 * (CONNECT_DATA=(SID=pdb09)(CID=(PROGRAM=perl)(HOST=a5071ue1plora04)(USER=oracle))) * (ADDRESS=(PROTOCOL=tcp)(HOST=172.18.76.29)(PORT=53096)) * establish * pdb09 * 12505 | |
4/2/24 5:57:08.000 AM | 2024-04-02T05:57:08.619205-04:00 |
Please share your sample event in a code block </> not an image of them?
Also, what settings do you currently have?
I am assuming you are looking to do this at ingest time rather than search time, please clarify?