All Apps and Add-ons

parsing log text to get a specific info

wxt4359
New Member

Hi I am newbie to splunk and trying to build a search query that can parse a specific text like below to get the sum of the AAA file content length but couldn't figure out on the search query for that. Any helps will be appreciated. Thanks.

AAA file content length is 67095 bytes
AAA file content length is 7095 bytes

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @wxt4359,
as @martin_mueller hinted, you have to extract the filename and length fields using a rex and the sum the values of the length field for each filename using stats, something like this:

index=your_index
| rex "^(?<filename>[^ ]+).*length\s+is\s+(?<legth>\d+)\sbytes"
| stats sum(length) AS total_length BY filename

You can test your regex at https://regex101.com/r/no5Gwk/1
You can find more details baour rex and stats command at the urls indicated by martin_mueller.

Ciao.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @wxt4359,
as @martin_mueller hinted, you have to extract the filename and length fields using a rex and the sum the values of the length field for each filename using stats, something like this:

index=your_index
| rex "^(?<filename>[^ ]+).*length\s+is\s+(?<legth>\d+)\sbytes"
| stats sum(length) AS total_length BY filename

You can test your regex at https://regex101.com/r/no5Gwk/1
You can find more details baour rex and stats command at the urls indicated by martin_mueller.

Ciao.
Giuseppe

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
0 Karma

to4kawa
Ultra Champion
....
| rex "(?<content_length>\d+)"
| stats sum(content_length) as total_bytes
0 Karma

wxt4359
New Member

Thank you all

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...