Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

how to extract time from multi line log

$
0
0
Dears, i have log that repeated every 10 min as below 16-02-08 Name Succ drop 04:26:50 Searches 12 0 04:27:00 Searches 17 0 04:27:10 Searches 12 0 firts line contain Date of the Day and each line contain different Timestamp i need to know how to extract each line with exact time i know that i can break events using Break_line option and also break multiple events using multikv but i couldn't extract Correct time for every event So please advise

Viewing all articles
Browse latest Browse all 47296

Trending Articles