Splunk Enterprise Security

Unable to pull similar number 53726516638.77 (in billion) using chart for past 7 days?

jimish
Explorer

Unable to pull similar number 53726516638.77 (in billion) using chart for past 7 days.

Dashboard only pulls data for only 1 day.

rex filed example :

 

rex field=_raw "(?ms)^\\w+/\\w+\\s+\\w+\\s+\\w+\\s+\\w+\\.\\s+\\w+/\\w+\\s+\\w+\\s+\\w+\\s+\\w+\\.\\s+\\w+\\s+\\w+\\s+\\w+\\s+\\w+\\s+\\w+:\\s+\\d+\\.\\d+\\s+\\w+\\s+\\w+\\s+\\w+\\s+\\w+\\s+\\w+:\\s+\\d+\\.\\d+\\s+\\w+\\s+\\w+\\s+\\w+\\s+:\\s+\\.\\d+\\s+\\w+\\s+\\w+\\s+\\w+\\s+\\w+\\s+\\w+\\s+\\w+\\s+\\w+:\\s+(?P<TotalAsset>[^ ]+)" offset_field=_extracted_fields_bounds | eval mytime=strftime(_time, "%b%d") |chart values(Total_Assets_Price) by mytime

log output :

Want to pull total asset on pricing and previous date but somehow only pulls data for 1 day

Capture.PNG

Labels (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Is data coming in same format every day? (try to run the search with time-range "Yesterday" and check.

 

Also give this a try

your base search
| rex field=_raw "Total Assets on Pricing Date:\s+(?P<TotalAsset>\S+)" offset_field=_extracted_fields_bounds | eval mytime=strftime(_time, "%b%d") |chart values(Total_Assets_Price) by mytime

View solution in original post

0 Karma

somesoni2
Revered Legend

Is data coming in same format every day? (try to run the search with time-range "Yesterday" and check.

 

Also give this a try

your base search
| rex field=_raw "Total Assets on Pricing Date:\s+(?P<TotalAsset>\S+)" offset_field=_extracted_fields_bounds | eval mytime=strftime(_time, "%b%d") |chart values(Total_Assets_Price) by mytime
0 Karma

jimish
Explorer

Thank you this rex expression is better and pulled data from past two days .

 

Tags (1)
0 Karma

somesoni2
Revered Legend

What output do you get and what output you want?

0 Karma

jimish
Explorer

Its only printing data for one day , for 20th also i need to see data as logs are updated as of 19th.

Capture.PNG

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...