Splunk Search

Collect values from syslog logging

admin_fred
New Member

Hello,

I am new to splunk and have the following question. Below is snippet from a syslog logging. I would like to show the value behind (fordblks): in a chart based on _time.

[10-25 06:22:01,010] [freecwmpUTCd main          728] INF (statistics) MEM:1187840  | Total allocated space (uordblks):      997960
[10-25 06:22:01,010] [freecwmpUTCd main          728] INF (statistics) MEM:1187840  | Total free space (fordblks):           189880

I have tried rex and split and mvindex commands but I don't get it to work yet. Could anyone point me in the right direction?

Tags (1)
0 Karma
1 Solution

renjith_nair
Legend

@admin_fred
Below should give you the value for fordblks and then you can chart.

|rex field=_raw "fordblks\):\s+(?<MY_VALUE>\d+)"
---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

admin_fred
New Member

The code below is working as expected:

my search |rex field=_raw "fordblks):\s+(?\d+)" | stats values(MY_VALUE) by  _time my_process

note: my_process is an additional field so the statistics for 'fordblks' will be spitted up for multiple processes, which is very nice addition.

I only notice the search updates (live search) can take quite long. Maybe due to my (slow) Intel Celeron processor.

0 Karma

renjith_nair
Legend

@admin_fred
Below should give you the value for fordblks and then you can chart.

|rex field=_raw "fordblks\):\s+(?<MY_VALUE>\d+)"
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

admin_fred
New Member

Thank you very much!

The code below works fine.

|rex field=_raw "fordblks):\s+(?\d+)" | table _time MY_VALUE

How can I now present information in a chart instead of table?

0 Karma

renjith_nair
Legend

@admin_fred,
If you have different values for time, then fields _time,MY_VALUE itself could be visualized in a graph.
Or stats values(MY_VALUE) by _time or chart max(MY_VALUE) by _time depends on your requirement.

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...