Splunk Search

success vs failed graph

muzeebm
Explorer

Hi, 

Below is the information from one of my logs. 

"Information","ajp-nio-127.0.0.1-8016-exec-642","11/24/20","13:30:14","CLIENT_URL","samlServices.processRequest: stuUserReturn: {""update_user_details"":1,""processByCf"":true,""USER_LOGIN"":""XXXXX@YYYY.org"",""userID"":""XXXXXXX"",""user_id"":XXXXX,""connection_name"":""XXXX"",""login"":""XXXXX@YYYY.org"",""userAttributes"":{""group_name"":""HR"",""telephone"":"""",""country"":1,""preferredLanguage"":"""",""login"":"""",""organisation"":""XXXXX English"",""last_name"":""XXXXXX"",""email"":""XXXX@YYYY.org"",""first_name"":""XXXX"",""company"":""XXXXX English""},""saml_id"":1,""loginStatus"":""success""}"

 

The last bit loginStatus"":""success" will be  loginStatus"":""failed" in case of failure. 

 

I want to create create a chart/dashboard where I can get number of success requests compared to failures over a period of time. eg 30 days

 

Can someone please help me sort this out. Thanks. 

 

M

Labels (1)
Tags (1)
0 Karma
1 Solution

muzeebm
Explorer

Thanks, looks like it worked. 👍 @ITWhisperer 

View solution in original post

0 Karma

muzeebm
Explorer

Thanks, looks like it worked. 👍 @ITWhisperer 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like

| rex "loginStatus\"\":\"\"(?<loginstatus>[^\"]+)"
| timechart count by loginstatus
0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...