Hello,
I am new to splunk and have the following question. Below is snippet from a syslog logging. I would like to show the value behind (fordblks): in a chart based on _time.
[10-25 06:22:01,010] [freecwmpUTCd main 728] INF (statistics) MEM:1187840 | Total allocated space (uordblks): 997960
[10-25 06:22:01,010] [freecwmpUTCd main 728] INF (statistics) MEM:1187840 | Total free space (fordblks): 189880
I have tried rex and split and mvindex commands but I don't get it to work yet. Could anyone point me in the right direction?
... View more