I have many agent versions and each row is displayed as the different version... Like the query is telling it to do.
I need help in the sense of would like to truncate evey period and digit to the single version digit.
6.3.0.0
6.2.1
7.3.3
7.21
To look like this:
6
7
There are a few ways to do that. Here's one
| rex field=version "(?<version>\d+)\."
There are a few ways to do that. Here's one
| rex field=version "(?<version>\d+)\."
you can use substr eval function
| eval version=substr(version,1,1)
useful search:
index=_internal sourcetype=splunkd group=tcpin_connections version=* os=* arch=* build=* hostname=* source=*metrics.log
| stats latest(version) as version,latest(arch) as arch,latest(os) as os,latest(build) as build by hostname
| eval version=substr(version,1,1)
| join hostname [ | metadata type=hosts index=*
| eval last_seen_hours=(now()-lastTime)/60/60
| table host, last_seen_hours
| rex field=host "(?<hostname>[^\.]+)" | fields - host ]
Regards
Ale