Splunk Search

How do you extract the number of orders processed?

orchapellico
Explorer

I am trying to use regex to get the number of orders processed in the example below.

Number for orders processed: 36
Time for Picking Wave in Secs: 29 secs
Time for label printing in Secs: 2 secs
Time for entire wave in Secs: 37 secs

I am using this but not seeing why is it isn't working.

rex field=_raw "Number for orders processed"\:\s"(?)\s(\d+)" 
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

When writing SPL in an Answers posting, be sure to surround the query in backticks (`) so the content is preserved.

Your rex command looks close, but not quite there. Try this. It looks for the label text followed by a colon and at least one space. It then looks for at least one digit and puts what it finds in the 'orders' field.

rex "Number for orders processed:\s+(?<orders>\d+)" 

regex101.com is an excellent resource for testing regular expressions.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

When writing SPL in an Answers posting, be sure to surround the query in backticks (`) so the content is preserved.

Your rex command looks close, but not quite there. Try this. It looks for the label text followed by a colon and at least one space. It then looks for at least one digit and puts what it finds in the 'orders' field.

rex "Number for orders processed:\s+(?<orders>\d+)" 

regex101.com is an excellent resource for testing regular expressions.

---
If this reply helps you, Karma would be appreciated.
0 Karma

orchapellico
Explorer

Thank you that is what I needed and makes more sense, I was close on this.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...