Extract value within quotes and plot on timechart

New Member


I am very new to splunk and i have data like this below:

"salary": "2000"

I have 1000's of events like this, I would like to extract only the integer 2000 and plot the value on timechart.

source="tcp:8050"  | search salary| rex _raw=".*(?P<sal>\d+).*" | timechart count as "SAL"

The above search is only returning the number of events having salary but not returning the actual value of 2000.
Requests help to achieve this!!!

try this,

your search here | rex field=_raw "\"salary\":\s+\"(?P<\d+>)\"" | timechart count by sal_value

