Splunk Search

How to extract some % values of specific parameters?

thaghost99
Path Finder

hi, i am a bit lost, i am trying to extract some % values of specific parameters. but with no luck

example i want to extract the anti-virus value of 12%

 

this is my command

| rex field=_raw "Anti-Spam\s*<(?<cpu>.*)>"

Gauges: Current
System
RAM Utilization 65%
Overall CPU load average 43%
CPU Utilization
MGA 20%
Anti-Virus 12%
Reporting 0%
Quarantine 0%

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

 Hi @thaghost99,

Below should work;

| rex field=_raw "Anti-Spam\s*(?<cpu>.*)"
If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

thaghost99
Path Finder

sorry i am missing the anti-virus.

 

here is the actual.

 

Gauges: Current
System
RAM Utilization 53%
Overall CPU load average 44%
CPU Utilization
MGA 34%
Anti-Spam 35%
Anti-Virus 0%
Reporting 0%
Quarantine 0%

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...