Splunk Search

Collect values from syslog logging

admin_fred
New Member

Hello,

I am new to splunk and have the following question. Below is snippet from a syslog logging. I would like to show the value behind (fordblks): in a chart based on _time.

[10-25 06:22:01,010] [freecwmpUTCd main          728] INF (statistics) MEM:1187840  | Total allocated space (uordblks):      997960
[10-25 06:22:01,010] [freecwmpUTCd main          728] INF (statistics) MEM:1187840  | Total free space (fordblks):           189880

I have tried rex and split and mvindex commands but I don't get it to work yet. Could anyone point me in the right direction?

Tags (1)
0 Karma
1 Solution

renjith_nair
Legend

@admin_fred
Below should give you the value for fordblks and then you can chart.

|rex field=_raw "fordblks\):\s+(?<MY_VALUE>\d+)"
---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

admin_fred
New Member

The code below is working as expected:

my search |rex field=_raw "fordblks):\s+(?\d+)" | stats values(MY_VALUE) by  _time my_process

note: my_process is an additional field so the statistics for 'fordblks' will be spitted up for multiple processes, which is very nice addition.

I only notice the search updates (live search) can take quite long. Maybe due to my (slow) Intel Celeron processor.

0 Karma

renjith_nair
Legend

@admin_fred
Below should give you the value for fordblks and then you can chart.

|rex field=_raw "fordblks\):\s+(?<MY_VALUE>\d+)"
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

admin_fred
New Member

Thank you very much!

The code below works fine.

|rex field=_raw "fordblks):\s+(?\d+)" | table _time MY_VALUE

How can I now present information in a chart instead of table?

0 Karma

renjith_nair
Legend

@admin_fred,
If you have different values for time, then fields _time,MY_VALUE itself could be visualized in a graph.
Or stats values(MY_VALUE) by _time or chart max(MY_VALUE) by _time depends on your requirement.

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...