Splunk Search

count by wildcard in field value

Toby_r
Loves-to-Learn

Hi,

I've following issue: Ive a dataset containing data like
Order number = 12345
Description = "AB: jdkjsd"
planned_date="12.3.2020"

Order number = 12346
Description = "BC: jdkjsd"
planned_date="12.3.2020"

Order number = 12347
Description = "BA: jdkjsd"
planned_date="12.3.2020"

 

now I'd like to have a table which counts me the number of events for "BC:*", "AB:*" OR "BA:*",... and so on - I'm quite new and google didnt helped me, can someone help? Thanks!

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| rex field=Description "(?<prefix>\w+)\:"
| stats count by prefix
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...