I've read a few posts here already but hoping to clarify some items that I have. I need regex (rex) a raw or list msg then perform a "stats count by field" on that field found.
When i login to splunk the view is defaulted to "List" results vs Raw results. Is this the default in spunk-cloud? Not that it matters to me but probably it matters when I create my Search in my Dashboard?
When I try to perform rex, I can't get the exact field that I need to do a stats count by that field and value that I need
The field that I need is "processingStatus”:”BIDDING_STARTED” then do stats count on this key, value. I think the List vs Raw view is throwing off the way rex is used? Any other recommendations?
Do I need to set something to stick to a certain view?
Thanks!
LIST VIEW: (with escape characters)
\"processingStatus\":\"BIDDING_STARTED\"
RAW VIEW:
msg: 2018-10-11 15:32:07.973 INFO 14 --- [aaa-8080-exec-6] a.b.c.shoppingCartController : Response = [{"resourceId”:”f133b31e0-1234-1234-1234-rt1204bf8122”,”customerId":4194562,"consumerKey":"f133b31e0-1234-1234-1234-rt1204bf8122","externalId":"SHOEX:201810090738498037101234: 201810090738498037101234","shoes":{"relativeId":"f133b31e0-1234-1234-1234-rt1204bf8122","externalId":"SHOEX:521900”,”name":"VaporFly","gender":"MALE","year":1,"birthDate":{"year”:2018,”month”:9,”day":1},"classification":{"model":"Runnning","brand":"NIKE","environment":"Road"},"classifications":{"model":"Runnning","brand":"NIKE","environment":"Road"}},"person":{"relativeId":"5e3b69e5-8586-4bbf-99fd-a42f38609c0b","externalId":"SHOEX:568156","name":{"first":"Kipchoge","last":"Eliud"},"postalAddresses":[{"parentResourceId":"5e3b69e5-8586-4bbf-99fd-a42f38609c0b","streetAddress":["123 INTERNATIONA PKWY"],"city":"New York","state":{"name":"New York","code”:”NY”},”postalCode”:”12345”,”country":{"name":"UNITED STATES","iso2code":"US","iso3code":"USA","system":"http://abc-open.org/iso/3166/"}}],"electronicAddresses":[{"parentResourceId":"f133b31e0-1234-1234-1234-rt1204bf8122","address":"Kipchoge1@gmail.com"}],"phoneNumbers":[{"parentResourceId":"f133b31e0-1234-1234-1234-rt1204bf8122","countryCallingCode":"1","number”:”1232131234”,”extension":"","capabilities":{"fax":false,"voice":true,"text":false}}]},"practitioner":{"relativeId":"f133b31e0-1234-1234-1234-rt1204bf8122","externalId":"SHOEX:1","name":{"first”:”PATRICK”,”last”:”EVANS”},”clinicName":"SHOEX","phoneNumbers":[{"countryCallingCode":"1","number”:”1231231234”,”extension":"","capabilities":{"fax":false,"voice":true,"text":false}}]},"shopping":{"relativeId":"f133b31e0-1234-1234-1234-rt1204bf8122","shippingMethod":"STANDARD"},"prescription":{"relativeId":"f133b31e0-1234-1234-1234-rt1204bf8122","product”:{“aac”:”0987778769”,”consumerSku":"2976672”,”shoeModelNumber”:”12308474”,”cartIndicator”:false},"quantity":{"value”:”253”,”units”:”1”},”invoice":{"invoiceNbr”:”12345678901”,”aisleNumber”:”1”}},”shoeProfile”:{“relativeId”:”aoej23094-h4h4h4-h4h4h-h3h45-123oje092384jd”,”styles":[{"effectivePeriod":{"start":{"date":{"year":2018,"month":10,"day":9},"time":{"hour":14,"minute":48,"second":4,"nano":687000000}}},"styleStatus":"Registered","styleType":{"codings":[{"code”:”123456-7”,”display”:”Shoe Weight","system":{"identifier":"http://shoe”,”name”:”VAPORFLY FLYKNIT”,”version":"V2”}}],”text":"Weight"},"value":{"quantity”:7.9,”uncertainty":0.0,"units":{"symbol":"lb","unitSystem”:”METRIC”}}}]},”createdDateTime":{"date":{"year":2018,"month”:10,”day”:1},”time":{"hour":14,"minute":48,"second":5,"nano”:124000000}},"updatedDateTime":{"date":{"year":2018,"month":10,"day":9},"time":{"hour":14,"minute":48,"second":11,"nano":377000000}},"status":"Processed","processingStatus”:”BIDDING_STARTED”,”links":[{"rel":"self","href":"https://coding.io/v1/ShoppingCarts/a47b31e0-7443-48a9-8d98-ac3204bf824a","template":{"variables":{"variables":[]},"baseUri":"https://coding.io/v1/ShoppingCarts/a47b31e0-7443-48a9-8d98-ac3204bf824a"}}]}]
... View more