<results preview='0'> <meta> <fieldOrder> <field>_bkt</field> <field>_cd</field> <field>_indextime</field> <field>_raw</field> <field>_serial</field> <field>_si</field> <field>_sourcetype</field> <field>_subsecond</field> <field>_time</field> <field>host</field> <field>index</field> <field>linecount</field> <field>source</field> <field>sourcetype</field> <field>splunk_server</field> </fieldOrder> </meta> <messages>
<msg type="DEBUG">base lispy: [ AND index::_internal ]</msg> <msg type="DEBUG">search context: user="admin", app="search", bs-pathname="/Users/fross/splunks/splunk-5.0.2/etc"</msg>
</messages>
<result offset='0'> <field k='_bkt'> <value><text>_internal~1~BC03CEFB-A9C5-4DF5-9D8D-2558AD6E6EA9</text></value> </field> <field k='_cd'> <value><text>1:4419005</text></value> </field> <field k='_indextime'> <value><text>1360608181</text></value> </field> <field k='_raw'><v xml:space='preserve' trunc='0'>02-11-2013 10:43:01.060 -0800 INFO Metrics - group=tpool, name=indexertpool, qsize=0, workers=6, qwork_units=0</v></field> <field k='_serial'> <value><text>0</text></value> </field> <field k='_si'> <value><text>fross-mbp15.local</text></value> <value><text>_internal</text></value> </field> <field k='_sourcetype'> <value><text>splunkd</text></value> </field> <field k='_subsecond'> <value><text>.060</text></value> </field> <field k='_time'> <value><text>2013-02-11 10:43:01.060 PST</text></value> </field> <field k='host'> <value><text>fross-mbp15.local</text></value> </field> <field k='index'> <value h='1'><text>_internal</text></value> </field> <field k='linecount'> <value><text>1</text></value> </field> <field k='source'> <value><text>/Users/fross/splunks/splunk-5.0.2/var/log/splunk/metrics.log</text></value> </field> <field k='sourcetype'> <value><text>splunkd</text></value> </field> <field k='splunk_server'> <value><text>fross-mbp15.local</text></value> </field> </result> <result offset='1'> <field k='_bkt'> <value><text>_internal~1~BC03CEFB-A9C5-4DF5-9D8D-2558AD6E6EA9</text></value> </field> <field k='_cd'> <value><text>1:4418999</text></value> </field> <field k='_indextime'> <value><text>1360608181</text></value> </field> <field k='_raw'><v xml:space='preserve' trunc='0'>02-11-2013 10:43:01.060 -0800 INFO Metrics - group=tpool, name=bundlereplthreadpool, qsize=0, workers=0, qwork_units=0</v></field> <field k='_serial'> <value><text>1</text></value> </field> <field k='_si'> <value><text>fross-mbp15.local</text></value> <value><text>_internal</text></value> </field> <field k='_sourcetype'> <value><text>splunkd</text></value> </field> <field k='_subsecond'> <value><text>.060</text></value> </field> <field k='_time'> <value><text>2013-02-11 10:43:01.060 PST</text></value> </field> <field k='host'> <value><text>fross-mbp15.local</text></value> </field> <field k='index'> <value h='1'><text>_internal</text></value> </field> <field k='linecount'> <value><text>1</text></value> </field> <field k='source'> <value><text>/Users/fross/splunks/splunk-5.0.2/var/log/splunk/metrics.log</text></value> </field> <field k='sourcetype'> <value><text>splunkd</text></value> </field> <field k='splunk_server'> <value><text>fross-mbp15.local</text></value> </field> </result>
</results> <results preview='0'> <meta> <fieldOrder> <field>_bkt</field> <field>_cd</field> <field>_indextime</field> <field>_raw</field> <field>_serial</field> <field>_si</field> <field>_sourcetype</field> <field>_subsecond</field> <field>_time</field> <field>host</field> <field>index</field> <field>linecount</field> <field>source</field> <field>sourcetype</field> <field>splunk_server</field> </fieldOrder> </meta>
<result offset='0'> <field k='_bkt'> <value><text>_internal~1~BC03CEFB-A9C5-4DF5-9D8D-2558AD6E6EA9</text></value> </field> <field k='_cd'> <value><text>1:4418632</text></value> </field> <field k='_indextime'> <value><text>1360608170</text></value> </field> <field k='_raw'><v xml:space='preserve' trunc='0'>127.0.0.1 - admin [11/Feb/2013:10:42:49.790 -0800] "POST /services/search/jobs/export HTTP/1.1" 200 440404 - - - 257ms</v></field> <field k='_serial'> <value><text>51</text></value> </field> <field k='_si'> <value><text>fross-mbp15.local</text></value> <value><text>_internal</text></value> </field> <field k='_sourcetype'> <value><text>splunkd_access</text></value> </field> <field k='_subsecond'> <value><text>.790</text></value> </field> <field k='_time'> <value><text>2013-02-11 10:42:49.790 PST</text></value> </field> <field k='host'> <value><text>fross-mbp15.local</text></value> </field> <field k='index'> <value h='1'><text>_internal</text></value> </field> <field k='linecount'> <value><text>1</text></value> </field> <field k='source'> <value><text>/Users/fross/splunks/splunk-5.0.2/var/log/splunk/splunkd_access.log</text></value> </field> <field k='sourcetype'> <value><text>splunkd_access</text></value> </field> <field k='splunk_server'> <value><text>fross-mbp15.local</text></value> </field> </result> <result offset='1'> <field k='_bkt'> <value><text>_internal~1~BC03CEFB-A9C5-4DF5-9D8D-2558AD6E6EA9</text></value> </field> <field k='_cd'> <value><text>1:4418626</text></value> </field> <field k='_indextime'> <value><text>1360608157</text></value> </field> <field k='_raw'><v xml:space='preserve' trunc='0'>127.0.0.1 - admin [11/Feb/2013:10:42:36.527 -0800] "POST /services/search/jobs/export HTTP/1.1" 200 4937 - - - 219ms</v></field> <field k='_serial'> <value><text>52</text></value> </field> <field k='_si'> <value><text>fross-mbp15.local</text></value> <value><text>_internal</text></value> </field> <field k='_sourcetype'> <value><text>splunkd_access</text></value> </field> <field k='_subsecond'> <value><text>.527</text></value> </field> <field k='_time'> <value><text>2013-02-11 10:42:36.527 PST</text></value> </field> <field k='host'> <value><text>fross-mbp15.local</text></value> </field> <field k='index'> <value h='1'><text>_internal</text></value> </field> <field k='linecount'> <value><text>1</text></value> </field> <field k='source'> <value><text>/Users/fross/splunks/splunk-5.0.2/var/log/splunk/splunkd_access.log</text></value> </field> <field k='sourcetype'> <value><text>splunkd_access</text></value> </field> <field k='splunk_server'> <value><text>fross-mbp15.local</text></value> </field> </result>
</results>