Splunk Search

extract string from _raw data


Hello need help to extract the number from this result:

Total number of files under /wmq/logs/AMXDEVRC120/active is: 184

i'm trying to get the total number of files from this directory and compare if over 500. 


thank you, 


Labels (1)


thanks for the help


0 Karma


Use rex.

... | rex "is: (?<numFiles>\d+)"
| stats sum(numFiles) as TotalFiles
| where TotalFiles > 500
If this reply helps you, an upvote would be appreciated.
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!