Splunk Search

Print rex result on search

arizoide
New Member

First, i'm sorry for my bad english.

Let me explain my problem.

I have to do a search on splunk, and in the result, get a specific value, between ": [44444]" (In this case, i want the value 44444.) and do a avg

I tried this: index=x host=y "my search" | rex field=_raw "(?<=: [)(.*?)(?=])" | timechart avg(ms)

Example response: hksdfhjksadhfjksadhfjksa [36278423] gdjsagdshdgfjsadf: [21234] ms

But don't work. I tried other things, but i don't know how to print the variable ms and know whats is in that.

Can anyone help me?

Thanks

AT

Tags (1)
0 Karma

somesoni2
Revered Legend

Try something like this

index=x host=y "my search" | rex field=_raw "\[(?<ms>\d+)\]\s*ms" | timechart avg(ms)
0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...