Splunk Dev

How to extract response time?

karthi2809
Builder

How to extract response time?

response_time:0.002941865 app_id:\"c232e3a2-cecb-4e81-9beb-3150710c9a0a\"

Extract response time only

0 Karma

vnravikumar
Champion

Hi

Try this

| makeresults 
| eval test="response_time:0.002941865 app_id:\"c232e3a2-cecb-4e81-9beb-3150710c9a0a\"" 
| rex field=test "response_time:(?P<response_time>[\S]+)"
0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...