Got the following: One field with 4 types of values/functions and another field that is the status of those functions such as INFO or ERROR.
I would like to cross this information to see each function how many ERROS or INFOs those got.
I was wondering if I could do this task with stats
, but the search command bellow is so far what i could get.
index="websphere_index" sourcetype="portoprint-app-*"
| rex "(?m)^\[.*\]\[.*\]\s+?(?<WEB_STATUS>([A-Z]+))\s+?[\w\.]+\s+?\[.*\]\s+?\w+\(\)"
| rex "(?m)^\[.*\]\[.*\]\s[A-Z]+(\s+?|\S+?).*\1\[.*\]\s(?<WEBSPHERE_FUNCTION>(\w+\(\)))"
| stats count(WEB_STATUS) by WEBSPHERE_FUNCTION
Thanks!
Instead of stats
, try chart, like:
... | chart count by WEBSPHERE_FUNCTION WEB_STATUS
Or you could do:
... | stats count by WEBSPHERE_FUNCTION WEB_STATUS
Instead of stats
, try chart, like:
... | chart count by WEBSPHERE_FUNCTION WEB_STATUS
Or you could do:
... | stats count by WEBSPHERE_FUNCTION WEB_STATUS
Exactly what I wanted ! Thank you