@gsmith Thanks for the reply and apologies for the late reply for some reason I may have missed the notification.
I guess the complexity that I am trying to solve is about the format of the data :
The data is : 0h:05m:06s
but in order to be useable I need to convert that in a time format but the H, M and S need to be removed.
So what I am looking for is how I can process the raw message as it is being ingested so that I can aggregated it over a period of time.
would it be using pipelines ?
I tried to use pipeline with a simple :
//let duration2 = regex("(\d+)h:(\d+)m:(\d+)s",to_string(asa_duration));