OMC HOW-TO: extracting additional time/date fields in log analytics
Summary
Log analytics already handles extracting log entry time, but sometimes there are other time/date elements you want to extract and analyze.Content
Background
Some log entries will have a log entry time, but will also have the start and end time of a process or transaction that you may want to capture into their own fields. After capturing the start and end time into their own fields, you can use query language eval functions to perform date manipulation on these fields for instance to get the duration between the two times. This document only applies to a single log entry have the additional time/date fields. If you are trying to connect separate log entries by some grouped field, look into the Link feature
Tagged:
1