Also have another doubt. I have written below query to get the specific output. index=xyz sourcetype="automation:csv" source="D:\\Intradiem_automation\\ACD_FILETRACKER.csv" | rex field=_raw "^(?P<A...
See more...
Also have another doubt. I have written below query to get the specific output. index=xyz sourcetype="automation:csv" source="D:\\Intradiem_automation\\ACD_FILETRACKER.csv" | rex field=_raw "^(?P<ACD>\w+\.\d+),(?P<ATTEMPTS>[^,]+),(?P<FAIL_REASON>[^,]*),(?P<INTERVAL_FILE>[^,]+),(?P<STATUS>\w+),(?P<START>[^,]+),(?P<FINISH>[^,]+),(?P<INGEST_TIME>.+)" | eval field_in_hhmmss=tostring(INGEST_TIME, "duration") | rename field_in_hhmmss AS INGESTION_TIME_HH-MM-SS | search ACD="*" ATTEMPTS="*" FAIL_REASON="*" INTERVAL_FILE="*" STATUS="*" START="*" FINISH="*" INGESTION_TIME_HH-MM-SS="*" | table ACD, ATTEMPTS, FAIL_REASON, INTERVAL_FILE,INTERVAL_FILE1, STATUS, START, FINISH, INGESTION_TIME_HH-MM-SS | dedup INTERVAL_FILE | sort -START I like to extract the filename "020624.0500" from Interval_file column and create another column name "Filename" beside the Interval_file column and before status column. Please help ACD ATTEMPTS FAIL_REASON INTERVAL_FILE STATUS START FINISH INGESTION_TIME_HH-MM-SS acd.55 1 NULL C:\totalview\ftp\switches\customer1\55\020624.0500 PASS 2024-02-06 11:32:30.057 +00:00 2024-02-06 11:32:52.274 +00:00 00:00:22 acd.55 1 NULL C:\totalview\ftp\switches\customer1\55\020624.0530 PASS 2024-02-06 12:02:30.028 +00:00 2024-02-06 12:02:54.151 +00:00 00:00:24 acd.85 1 NULL C:\totalview\ftp\switches\customer1\85\020624.0500 PASS 2024-02-06 11:31:30.021 +00:00 2024-02-06 11:31:40.788 +00:00 00:00:10