We need to start alerting on the results of the IIS time taken field. Any idea how to extract that field so it can be easily searched? I am hasving no luck at all.
2012-04-25 21:23:31 ::1 POST /PU.PDS.ExternalServices/SolutionExecution/ExternalSolutionExecution.svc - 80 - ::1 - 200 0 0 11734
I need to sertup an alert on the last field output "11734" when it gets over 10000.
asked 26 Apr '12, 10:55
Try to see if adding this in your search works.
sourcetype=iis_logs| rex "(?<time_taken>w*)$"
See if the field time_taken is matching the last digits correctly. Then create an alert and make it alert if time_taken > 10000
answered 26 Apr '12, 13:38