Splunk Search

After extracting a field with rex, what is the most efficient way to call stats on a specific value within this field?

pred15
Engager

Hi, any help with this would be appreciated!

 

rex field=msg.message "loc=(?<place>\d+)" | search place="16" | stats count by "place"  

The extracted field is place. The specific place I am searching for is "16". Is there a more efficient way to search for a specific place before calling stats? 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
Looks fine to me.
---
If this reply helps you, Karma would be appreciated.

pred15
Engager

@richgalloway Is there any more efficient way to do this such as bypassing the field extraction if I am only looking for a singular specific "place"?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm not sure if it's "more efficient", but you could try this search.  Compare this your other one using Job Inspector to see which works best.

| where match(msg.message, "loc=16")| stats count
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...