I am hardly trying to extract the Duration value (in the example below: 10.400) using grok and to create a field Conference_duration.
The reason for the extraction is that I would like to summarize it or to receive an avarage value based on a specific timeframe
Any idea how to do this? I am done
<134>Feb 27 21:58:03.439 xxxxnode01 2018-02-27 21:58:03,439 Level="INFO" Name="administrator.conference" Message="Conference has been stopped." Conference="Heinz VMR" Service-tag="" Service-type="conference" Duration="10.400"