Splunk Search

After extracting a field with rex, what is the most efficient way to call stats on a specific value within this field?

pred15
Engager

Hi, any help with this would be appreciated!

 

rex field=msg.message "loc=(?<place>\d+)" | search place="16" | stats count by "place"  

The extracted field is place. The specific place I am searching for is "16". Is there a more efficient way to search for a specific place before calling stats? 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
Looks fine to me.
---
If this reply helps you, Karma would be appreciated.

pred15
Engager

@richgalloway Is there any more efficient way to do this such as bypassing the field extraction if I am only looking for a singular specific "place"?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm not sure if it's "more efficient", but you could try this search.  Compare this your other one using Job Inspector to see which works best.

| where match(msg.message, "loc=16")| stats count
---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...