Splunk Search

How to extract some % values of specific parameters?

thaghost99
Path Finder

hi, i am a bit lost, i am trying to extract some % values of specific parameters. but with no luck

example i want to extract the anti-virus value of 12%

 

this is my command

| rex field=_raw "Anti-Spam\s*<(?<cpu>.*)>"

Gauges: Current
System
RAM Utilization 65%
Overall CPU load average 43%
CPU Utilization
MGA 20%
Anti-Virus 12%
Reporting 0%
Quarantine 0%

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

 Hi @thaghost99,

Below should work;

| rex field=_raw "Anti-Spam\s*(?<cpu>.*)"
If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

thaghost99
Path Finder

sorry i am missing the anti-virus.

 

here is the actual.

 

Gauges: Current
System
RAM Utilization 53%
Overall CPU load average 44%
CPU Utilization
MGA 34%
Anti-Spam 35%
Anti-Virus 0%
Reporting 0%
Quarantine 0%

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...