Relative Content

Tag Archive for sumologic

How to get +/- 1 seconds logs information along with existing sumo log query?

“BlockedThreadChecker” AND ” – Thread Thread” AND ” has been blocked” | parse regex “Thread Thread[.*?] has been blocked for (?<blocked_time_ms>d+) ms” | where blocked_time_ms != “” | fields _raw, _messageTime , blocked_time_ms // Step 2: Create a transaction around the identified log entry within a +/-1 second window | where _messageTime >= _messageTime – […]