Hi,
I am very new to splunk and i have data like this below:
"salary": "2000"
I have 1000's of events like this, I would like to extract only the integer 2000 and plot the value on timechart.
source="tcp:8050" | search salary| rex _raw=".*(?P<sal>\d+).*" | timechart count as "SAL"
The above search is only returning the number of events having salary but not returning the actual value of 2000.
Requests help to achieve this!!!
Thanks!!
@skenkere
try this,
your search here | rex field=_raw "\"salary\":\s+\"(?P<\d+>)\"" | timechart count by sal_value