Splunk Search

extacting time

kumar518g
Explorer

hi ,
Please tell me how to extract 997 from the below statement

2013-01-30 19:53:39,995 com.cisco.cts.som.svosubmit.service.entitlement.dao.CCOEntitlementCache - End of the method getCCOEntitlement in com.cisco.cts.som.

Tags (2)
0 Karma
1 Solution

Ron_Naken
Splunk Employee
Splunk Employee

Do you mean how do you capture the 995 to a separate field? Use the Interactive Field Extractor (IFX):
http://docs.splunk.com/Documentation/Splunk/5.0.1/Knowledge/ExtractfieldsinteractivelywithIFX

You might also find it very beneficial to walk through the full tutorial:
http://docs.splunk.com/Documentation/Splunk/5.0.1/Tutorial/WelcometotheSplunkTutorial

View solution in original post

Ron_Naken
Splunk Employee
Splunk Employee

Do you mean how do you capture the 995 to a separate field? Use the Interactive Field Extractor (IFX):
http://docs.splunk.com/Documentation/Splunk/5.0.1/Knowledge/ExtractfieldsinteractivelywithIFX

You might also find it very beneficial to walk through the full tutorial:
http://docs.splunk.com/Documentation/Splunk/5.0.1/Tutorial/WelcometotheSplunkTutorial

kumar518g
Explorer

yes exactly,am very new to SPLUNK thx for your quick response now i got it how to extract fields

thx

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...