How to generate a chart based on Duration (x-axis) and timestamp (y-axis)?
12/19/2016 10:30:53 AM
LogName=JHApplication
... 7 lines omitted ...
RecordNumber=23080258
Keywords=Classic
Message=Action=ConsumeMessage, ConsumerType=InprocConsumer, ConsumerTypeName=WorkflowEndpoint, ConsumerMethodName=CustomerUpdateResponse, ConsumerParam=XmlNode, MessageId=1b411832-3625-4c19-aaf6-22a258a4dabd\1844534213, Duration=0.0284597
Strange. It's in standard key value pair format and should've been extract. Try something like this
index=* host=*MQ004 Duration | rex "Duration=(?<Duration>\d+(\.\d+)*)" |stats values(Duration) as Duration by _time
OR
index=* host=*MQ004 Duration | rex "Duration=(?<Duration>\d+(\.\d+)*)" |timechart avg(Duration) as Duration
Strange. It's in standard key value pair format and should've been extract. Try something like this
index=* host=*MQ004 Duration | rex "Duration=(?<Duration>\d+(\.\d+)*)" |stats values(Duration) as Duration by _time
OR
index=* host=*MQ004 Duration | rex "Duration=(?<Duration>\d+(\.\d+)*)" |timechart avg(Duration) as Duration
thank you so much.... its working
Try this
your base search | stats values(Duration) as Duration by _time
index=* host=*MQ004 Duration|stats values(Duration) as Duration by _time
it is showing only the _time but it is not displaying the Duration value, every minute it is generating 10 to 20 messages
Is Duration field already extracted (can you see the field Duration in the field sidebar)? If not then try something like this
no i can't see Duration field on the left side