<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Extract a specific value and make a visualization with time in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extract-a-specific-value-and-make-a-visualization-with-time/m-p/660987#M228207</link>
    <description>&lt;P&gt;I have regular traffic passing through my server. The server has the IP&amp;nbsp;10.41.6.222&lt;/P&gt;&lt;P&gt;My goal is to extract the Rate /sec passing through the server and&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;to be able to see theRate /sec in a graph an having x asis showing time and y axis Rate /sec (extracted values).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-----------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Rate 0/sec : Bytes 9815772 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 402/sec : Bytes 9816135 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 139587/sec : Bytes 10004146 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 147636/sec : Bytes 10009645 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 69967/sec : Bytes 10358668 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 69967/sec : Bytes 10361672 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 69967/sec : Bytes 10364579 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 69967/sec : Bytes 10364667 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 49661/sec : Bytes 10371887 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 217793/sec : Bytes 10700517 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 353829/sec : Bytes 10944230 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 93689/sec : Bytes 10946290 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 82030/sec : Bytes 10950753 : from owa client to vs_owa with address &lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2023 10:05:12 GMT</pubDate>
    <dc:creator>john_snow00</dc:creator>
    <dc:date>2023-10-17T10:05:12Z</dc:date>
    <item>
      <title>Extract a specific value and make a visualization with time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-a-specific-value-and-make-a-visualization-with-time/m-p/660987#M228207</link>
      <description>&lt;P&gt;I have regular traffic passing through my server. The server has the IP&amp;nbsp;10.41.6.222&lt;/P&gt;&lt;P&gt;My goal is to extract the Rate /sec passing through the server and&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;to be able to see theRate /sec in a graph an having x asis showing time and y axis Rate /sec (extracted values).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-----------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Rate 0/sec : Bytes 9815772 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 402/sec : Bytes 9816135 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 139587/sec : Bytes 10004146 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 147636/sec : Bytes 10009645 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 69967/sec : Bytes 10358668 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 69967/sec : Bytes 10361672 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 69967/sec : Bytes 10364579 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 69967/sec : Bytes 10364667 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 49661/sec : Bytes 10371887 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 217793/sec : Bytes 10700517 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 353829/sec : Bytes 10944230 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 93689/sec : Bytes 10946290 : from owa client to vs_owa with address 10.41.6.166:443:10.41.6.222Rate 82030/sec : Bytes 10950753 : from owa client to vs_owa with address &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 10:05:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-a-specific-value-and-make-a-visualization-with-time/m-p/660987#M228207</guid>
      <dc:creator>john_snow00</dc:creator>
      <dc:date>2023-10-17T10:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Extract a specific value and make a visualization with time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-a-specific-value-and-make-a-visualization-with-time/m-p/660991#M228208</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261561"&gt;@john_snow00&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry, where is the timestamp?&lt;/P&gt;&lt;P&gt;if it isn't contained in the event, it's added by Splunk.&lt;/P&gt;&lt;P&gt;Anyway, you could run something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| rex "Rate\s+(?&amp;lt;Bytes&amp;gt;\d+)\/sec"
| eval MB=Bytes/1024/1024
| timechart sum(MB) AS MB&lt;/LI-CODE&gt;&lt;P&gt;I also added the regex to extract the field, if you already have it, don't use my regex.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 10:48:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-a-specific-value-and-make-a-visualization-with-time/m-p/660991#M228208</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-17T10:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Extract a specific value and make a visualization with time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-a-specific-value-and-make-a-visualization-with-time/m-p/661015#M228218</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;SPAN&gt;Giuseppe. Can you please explain line after line ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 13:09:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-a-specific-value-and-make-a-visualization-with-time/m-p/661015#M228218</guid>
      <dc:creator>john_snow00</dc:creator>
      <dc:date>2023-10-17T13:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Extract a specific value and make a visualization with time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-a-specific-value-and-make-a-visualization-with-time/m-p/661019#M228222</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261561"&gt;@john_snow00&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I try to explain:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt; --- it's your search, e.g. index=your_index sourcetype=your_sourcetype ---
| rex "Rate\s+(?&amp;lt;Bytes&amp;gt;\d+)\/sec" --- Bytes field extraction ---
| eval MB=Bytes/1024/1024 --- change measure of Bytes field from bytes to MB ----
| timechart sum(MB) AS MB --- sum of the traffic foe time periods, it's possible to define this span period ---&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 13:19:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-a-specific-value-and-make-a-visualization-with-time/m-p/661019#M228222</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-17T13:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Extract a specific value and make a visualization with time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-a-specific-value-and-make-a-visualization-with-time/m-p/661025#M228225</link>
      <description>&lt;P&gt;Thank you for the&amp;nbsp; explanation. The rate in seconds you see above&amp;nbsp; are produced by Loadbalancer upon incoming TCP requests.&amp;nbsp; The logs are later pushed to splunk for analysis.&lt;/P&gt;&lt;P&gt;I d'ont want to carry any futher calculation. I just want to&lt;STRONG&gt; extract the rate /sec from the raw and present it upon time (x-axis).&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 13:43:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-a-specific-value-and-make-a-visualization-with-time/m-p/661025#M228225</guid>
      <dc:creator>john_snow00</dc:creator>
      <dc:date>2023-10-17T13:43:06Z</dc:date>
    </item>
  </channel>
</rss>

