Hi all. I am new to using splunk. I am trying to be able to extract data from a log for the last 15 minutes. I try to generate the alert, every time an implementation of "Weblogic AdminServer" is made on the different hosts we have with splunk I would need to know who made it, host, application and cluster. I used raw to extract it but it didn't work index=wls sourcetype=wls_adminserver host=EWL1522 user=<torrelia> app= consumer cluster=homo3.8_cl1 ####<Jul 24, 2020, 4:27:27,117 PM ART> <Info> <J2EE Deployment SPI> <EWL1522> <AdminServer> <[ACTIVE] ExecuteThread: '48' for queue: 'weblogic.kernel.Default (self-tuning)'> <torrelia> <> <4e1f868c-178a-4316-8cc0-a631e22c8aee-0014f65f> <1595618847117> <[severity-value: 64] [rid: 0] [partition-id: 0] [partition-name: DOMAIN] > <BEA-260121> <Initiating start operation for application,consumer#1.0 [archive: null], to homo3.8_cl1 .> anyone who can help me thanks.
... View more