that's what i got when i put the first expression
6 events like this one
1 » 4/3/12
11:40:58.727 AM 04-03-2012 11:40:58.727 +0200 INFO Metrics - group=udpin_connections, 192.168.0.111:5410, sourcePort=5410, _udp_bps=0.00, _udp_kbps=0.00, _udp_avg_thruput=0.00, _udp_kprocessed=0.00, _udp_eps=0.00host=lab2008 Options| sourcetype=splunkd Options| source=C:\Program Files\Splunk\var\log\splunk\metrics.log Options
and when i put the second expression , it doesn't give me anything
what i should do ??
... View more