Using the regex to get establish field name can be a pretty big pain.
Unless there's a good reason not to, I'd recommend logging the CPU Time within the .log file as something like: "CPU_Time=1133.982" (minus the quotation marks)
Splunk will automatically create the field "CPU_Time" if you log your information this way. It's extremely convenient.
... View more