Hi Jon,
I am trying to something like this:
I have this kind of info in my splunk logs
"BatchService BatchService;ProcessedTime:2896;RequestsProcessed:30"
would like to extract ProcessedTime and want to chart on ProcessedTime.
I tried this but does not give any results.
... batch ProcessedTime RequestsProcessed | rex .*ProcessedTime=(?P \d+) | where ProcessedTime > 10000
What am i doing wrong here?
... View more
Hi,
This is a very useful topic for what I am doing as well.
Can someone explain what is the .* for before the Time in ("... | rex .*Time=(?P \d+) | ...")
... View more