Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to merge multiple messages into a single message with a single timestamp based on my sample data?

$
0
0
I have a limitation of message size from the originating system and need to merge a message. The messages are separated for the first message by `...` (three periods) and the beginning and end of the middle part of the message is preceded and ended by `...` (three periods). The end of the message is ended by `...` (three periods). Any advice to merge this into a single message with a single date / time stamp?<14>Jul 21 11:32:15 localhost dayOfYear=203,year=2016,item_type=file,anomaly.timecreated=2016-07-21T17:58:57.000Z,weekOfWeekyear=29,source=api,type=workflow,millisOfDay=64737000,monthOfYear=7,incident_id=0:2427:3210:7242e229be5a0203a61a52c0b022cf9a7ed8ee96:5121b8941fe32040f99615c2f28a814f7397e865:2064:1469123937000,minuteOfDay=1078,collaborators=[{type=collaborator, id=file:/personal/bill_shnchannel1_onmicrosoft_com:/personal/bill_shnchannel1_onmicrosoft_com/Documents/INTERNAL ONEDRIVE FOLDER Shared/9mb File.pptx:bill@shnchannel1.onmicrosoft.com, user=bill@shnchannel1.onmicrosoft.com, role=editor, externally_shared=false}, {type=collaborator, id=file:/personal/bill_shnchannel1_onmicrosoft_com:/personal/bill_shnchannel1_onmicrosoft_com/Documents/INTERNAL ONEDRIVE FOLDER Shared/9mb File.pptx:bill@skyhighchannel.net, user=bill@skyhighchannel.net, role=editor, externally_shared=false}, {type=collaborator, id=file:/personal/bill_shnchannel1_onmicrosoft_com:/personal/bill_shnchannel1_onmicrosoft_com/Documents/IN...<14>Jul 21 11:32:15 localhost ...TERNAL ONEDRIVE FOLDER Shared/9mb File.pptx:bill@skyhighchannel.net, user=bill@skyhighchannel.net, role=viewer, externally_shared=false}, {type=collaborator, id=file:/personal/bill_shnchannel1_onmicrosoft_com:/personal/bill_shnchannel1_onmicrosoft_com/Documents/INTERNAL ONEDRIVE FOLDER Shared/9mb File.pptx:chitty@outlook.com, user=chitty@outlook.com, role=editor, externally_shared=true}, {type=collaborator, id=file:/personal/bill_shnchannel1_onmicrosoft_com:/personal/bill_shnchannel1_onmicrosoft_com/Documents/INTERNAL ONEDRIVE FOLDER Shared/9mb File.pptx:external@shnchannel1.onmicrosoft.com, user=external@shnchannel1.onmicrosoft.com, role=editor, externally_shared=false}],id=0,userGroup=-1,millisOfSecond=0,afterNow=false,userAction=Deleted,equalNow=false,last_executed_response_label=Deleted,userRiskLevel=high,matches=[{type=match, count=0}],anomaly.timeupdated=2016-07-21T17:58:57.000Z,dayOfMonth=21,name=9mb File.pptx,shared_link=false,fixed=true,yearOfEra=2016,millis=146912...<14>Jul 21 11:32:15 localhost ...3937000,actions=[{type=policy_violation_response_action, name=DELETE, weight=5, remediation_label=Delete, response_label=Deleted}],minuteOfHour=58,status=new,tenant_id=2427,riskLevel=high,policy_id=2064,weekyear=2016,secondOfMinute=57,dayOfWeek=4,era=1,yearOfCentury=16,secondOfDay=64737,similairCount=0,serviceId=3210,key=792089AD3C231A6B30AAAB7EA201659D64F52B26,timestamp=2016-07-21T17:58:57.000+0000,severity=2,userDisplayName=DA1773DD3F1E8773C342EF10879573D1BBC39063,policy_name=1.3 9MB File Size,serviceName=OneDrive,userId=-1,riscValue=3.0,beforeNow=true,response=Deleted,centuryOfEra=20,hourOfDay=17,anomalyCategoryId=0,activityType=-1,

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>