I have a log which looks like follows:
||pool-2-thread-1|| INFO com.tmobile.sfdc.reports.service.OpportunityService - OPPORTUNITY_JOB: List size: 41 ||pool-2-thread-1|| INFO com.tmobile.sfdc.reports.service.OpportunityService - OPPORTUNITY_JOB: List size: 140
I want to get the sum of the numbers(140+41+..), And I have tried the below query
base search| rex field=_raw "List size\"\:\"(?<size>[^\"]+)" | stats sum(size)
But it returns nothing. Can anyone please suggest me what am doing wrong.
@elliotproebstel how can change the above query if it is the date. For eg: if I contains the log like
||pool-2-thread-1|| INFO com.tmobile.sfdc.reports.batch.listener.OrderJobListener - ORDERJOB: ACTIVE at STARTTIME: 2018-05-07T06:04:46.087Z
and I want to get the value "2018-05-07T06:04:46.087Z"
How about this:
base search | rex field=_raw "(?<date>[^ ]+$)"
Here's a demo:
This regex is collecting everything between the last space and the end of the line and assigning it to a field called