Example: Retrieve the timestamp as a date format
To enrich the event message, perform the following steps:
Actions used in the example
The following actions are used in the example:
- Variable
- Enrich
For more information about actions, see Actions-for-advanced-and-time-based-enrichment.
To define the event selection criteria
- Select Configuration > Event Policies and click Create.
- In the Event Selection Criteria, define a condition to select events from the class EVENT that contain the message "testTime".
The following image illustrates how the event selection criteria will look:
To learn how to construct the event selection criteria, see Creating-and-enabling-event-policies.
To build the policy workflow
On the Advanced Enrichment page, perform the following steps to build the policy workflow:
Failed to execute the [excerpt-include] macro.
- Add the Variable action to retrieve the current timestamp in the specified date format and to store the result of the CurrentFormattedTimeStamp function as the variable value.
- Add an Enrich action to enrich the message with the formatted timestamp.
Results
The resulting policy workflow retrieves the timestamp as a date format as shown in the following image:
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*