Hi I have log file like this:
2021-06-15 13:39:47,762 INFO [APP] Exiting method , duration[109] User: general || method: findTypeMaps started at [1623748187753]
2021-06-15 13:39:47,738 INFO [APP] Exiting method , duration[101] User: general || method: findString started at [1623748187728]
2021-06-15 13:39:47,738 INFO [APP] Exiting method , duration[121] User: general || method: collectName started at [1623748187728]
I want to create chart that show method name duration over time on chart that able me to select method name.
like this:
Try this
| rex "duration\[(?<duration>\d+)\].*?method:\s(?<method>[^\s]+)"
| xyseries _time method duration
Try this
| rex "duration\[(?<duration>\d+)\].*?method:\s(?<method>[^\s]+)"
| xyseries _time method duration
Thank you for reply, it work for first part of my question.
but how can I show list of method on dashboard that when user select them just show that method on chart?
Thanks,
Depends on how you want to select the method and how you want that to affect what is on the chart. You could have a dropdown which is populated by a search query and sets a token that is used as a filter on the search for the chart, or you could have a table with similar information and use a drilldown from the table to set the token for the filter. If you want to do it the other way around i.e. click on the chart and drilldown to set a token to change what is displayed in a table.
I don't familiar with tokens, would you please tell me simple example?
another problem is, when I set time scope "real-time" (from 5min to NOW) it will be freeze for while, after that show chart. Is it possible reducing data points on chart. For e.g instead of show 1000 duration points on each minute for one method, just show one point that average of all those 1000 duration points.
is it possible to do this more efficient?