Hi all, I am completely new to Splunk so I apologize if this has been asked/answered. I did review the past discussions but could not find a solution to my question. I have incoming logs that look similar to this 28 Feb 2021 13:53:23,815[MANDATORY][JAS]Initiating EnterpriseOne startup using configuration location (default_path) as 'C:\jde_home\SCFHA\targets\HTML_PD1_82\config'. I would like to be able to search for the string "Initiating EnterpriseOne startup " and create a dashboard table showing the date, time and the substring HTML_PD1_82. The idea being, I would like to keep track of when each machine was restarted. Can anyone help with the Search pattern? Thanks in advance. Bruce
... View more