Thanks, and you are right I was trying to extract in myMsgId.
I looked at my data again and there is a minor issue. There is a request xml and response xml. Response xml has both elements <messageId> and <refToMessageId>. Request xml only has <messageId>. So the regex is capturing the messageId element, whereas I need to match it with <refToMessageId>. Can regex be modified to match it with refToMessageId, and if refToMessageId is not avaialble then match with messageId.
MessageId from request matches with refToMessageId from response. So I am trying to use these elements to evaluate response time.
("xyzRequest>" OR "xyzResponse>" ) "-fd9035a:151642200c0:-37c2" | stats earliest(_time) AS startTime, latest(_time) AS endTime | eval responseTime=endTime-startTime
This will extract from
refToMessageId and get one value in a new field called
\<refToMessageId\>(?<myRefMsgId>[^\<]+) | eval msgId=coalesce(myMsgId, myRefMsgId)
For what you are trying to do, have you looked at the
transaction command. You could do something like
.. | transaction msdId startswith="xyzRequest" endswith="xyzResponse" | table msgId duration