Assuming you plan to run this search every hour, try something like this
host="10.102.165.212" sourcetype=_json | spath| WHERE LIKE(master, "master") | stats latest('extra.memory') AS Current earliest('extra.memory') as LastHour | where Current>=LastHour*1.5
... View more
Thanks for your help,
The final query is... I didin't know regex101.com, very useful !!!
^((.*)(eng\-builds\/)(?P[^\/]+))|(?:[^\/\n]*\/){2}(?P[^\-]+)
... View more