Splunk Search

HI Team , i want to extract 8.9 value from this string " service error rate 50x 8.976851851851853". can you please help

Hemant_h
Engager

" service error rate 50x 8.976851851851853"

field = " service error rate 50x 8.976851851851853"
need to extract 8.9 value from above string.

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Use the rex statement, for example this regex

| makeresults
| eval field = " service error rate 50x 8.976851851851853"
| rex field=field "service error rate\s+\w+\s+(?<value>\d+\.\d)"

 (this is an example you can run in a search window).

Change your regex statement to match what you expect in the data 

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...