Heres what i'm trying to accomplish: requestID status 123456 errored 321654 Success 789456 errored I'm Newbie, Maybe i'm going about this all wrong, and there maybe another way....but i don't think so based on what info i have. but heres what i got so far. I'm probably over-thinking this. index=someindex sourcetype=sometype "request syntax" OR "error syntax" OR "success syntax" | rex field=_raw "request id: '(?<requestID>\d+)',\text" | rex field=_raw ".*(?<error>Error response received)\stext" | rex field=_raw ".*(?<Success>Database request executed):\stext" | eval requestID =if(requestID=(error),"Errored", "Success")
... View more