Got the following:
One field with 4 types of values/functions and another field that is the status of those functions such as INFO or ERROR.
I would like to cross this information to see each function how many ERROS or INFOs those got.
I was wondering if I could do this task with stats, but the search command bellow is so far what i could get.
| rex "(?m)^\[.*\]\[.*\]\s+?(?<WEB_STATUS>([A-Z]+))\s+?[\w\.]+\s+?\[.*\]\s+?\w+\(\)"
| rex "(?m)^\[.*\]\[.*\]\s[A-Z]+(\s+?|\S+?).*\1\[.*\]\s(?<WEBSPHERE_FUNCTION>(\w+\(\)))"
| stats count(WEB_STATUS) by WEBSPHERE_FUNCTION