Splunk Search

How do you extract the number of orders processed?

orchapellico
Explorer

I am trying to use regex to get the number of orders processed in the example below.

Number for orders processed: 36
Time for Picking Wave in Secs: 29 secs
Time for label printing in Secs: 2 secs
Time for entire wave in Secs: 37 secs

I am using this but not seeing why is it isn't working.

rex field=_raw "Number for orders processed"\:\s"(?)\s(\d+)" 
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

When writing SPL in an Answers posting, be sure to surround the query in backticks (`) so the content is preserved.

Your rex command looks close, but not quite there. Try this. It looks for the label text followed by a colon and at least one space. It then looks for at least one digit and puts what it finds in the 'orders' field.

rex "Number for orders processed:\s+(?<orders>\d+)" 

regex101.com is an excellent resource for testing regular expressions.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

When writing SPL in an Answers posting, be sure to surround the query in backticks (`) so the content is preserved.

Your rex command looks close, but not quite there. Try this. It looks for the label text followed by a colon and at least one space. It then looks for at least one digit and puts what it finds in the 'orders' field.

rex "Number for orders processed:\s+(?<orders>\d+)" 

regex101.com is an excellent resource for testing regular expressions.

---
If this reply helps you, Karma would be appreciated.
0 Karma

orchapellico
Explorer

Thank you that is what I needed and makes more sense, I was close on this.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...