Splunk Search

extacting time

kumar518g
Explorer

hi ,
Please tell me how to extract 997 from the below statement

2013-01-30 19:53:39,995 com.cisco.cts.som.svosubmit.service.entitlement.dao.CCOEntitlementCache - End of the method getCCOEntitlement in com.cisco.cts.som.

Tags (2)
0 Karma
1 Solution

Ron_Naken
Splunk Employee
Splunk Employee

Do you mean how do you capture the 995 to a separate field? Use the Interactive Field Extractor (IFX):
http://docs.splunk.com/Documentation/Splunk/5.0.1/Knowledge/ExtractfieldsinteractivelywithIFX

You might also find it very beneficial to walk through the full tutorial:
http://docs.splunk.com/Documentation/Splunk/5.0.1/Tutorial/WelcometotheSplunkTutorial

View solution in original post

Ron_Naken
Splunk Employee
Splunk Employee

Do you mean how do you capture the 995 to a separate field? Use the Interactive Field Extractor (IFX):
http://docs.splunk.com/Documentation/Splunk/5.0.1/Knowledge/ExtractfieldsinteractivelywithIFX

You might also find it very beneficial to walk through the full tutorial:
http://docs.splunk.com/Documentation/Splunk/5.0.1/Tutorial/WelcometotheSplunkTutorial

kumar518g
Explorer

yes exactly,am very new to SPLUNK thx for your quick response now i got it how to extract fields

thx

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...