Hello, I am trying to extract data, specifically time data in hh:mm:ss:nn format and put it on a table. When I do, I get no results to show up on my code.
| makeresults | eval _raw="11/05/2019 10:21:04 AM LogName=Application SourceName=RoboticLogging EventCode=0 EventType=4 Type=Information ComputerName=WTWFBVZP.UNITOPR.UNITINT.TEST.STATEFARM.ORG TaskCategory=%1 OpCode=Info RecordNumber=51614 Keywords=Classic Message=<Robotics Workstation=\"WTWFBVZP\" UserID=\"UNTOPR\OE1OTD\" Department=\"HRSS_NEO\" TaskID=\"Daily NEO Report\" Automation=\"NEO_P_SplunkMetrics\" Message=\"Number of supervisor reminder memos sent: 6,Number of New Employees in NEO Report without job title Temporary Agy Svc Asst: 988,Number of New Employees in NEO Report with job title Temporary Agy Svc Asst: 23,Duration: 00:01:50.5270509\" AdditionalInfo1=\"NA\" AdditionalInfo2=\"NA\"" | kv | eval _time=mvindex(split(_raw," "),0) | eval _time=strptime(_time,"%m/%d/%Y %T %p") | fieldformat _time=strftime(_time,"%m/%d/%Y %T %p") | rex "Message=\"(?<Message>[^\"]+)\"" | table _time LogName SourceName EventCode EventType Type ComputerName TaskCategory OpCode RecordNumber Keywords ,Workstation UserID Department TaskID Automation Message AdditionalInfo1 AdditionalInfo2 | appendpipe [eval _raw = Message | eval _raw = replace(_raw,"(\d+:\d+:\d+\.\d+)","\"\1\"") | extract pairdelim="," kvdelim=":" | fields - _raw] | selfjoin Message
post a sample of your data please
Added my data sample to post.
can you just post it to your question?
I can't. It won't let me post the whole data.