Splunk Search

How to compare numbers before and after a special char?

HelloItsMe76
Explorer

Hello, 

I have a log file that spits out data like the below. I want to be able to evaluate the the numbers either side of the "/" and alert if they are not the same. How can i do this? The will only be 1 "/" per line. The last line below that has "1/3" would be the only line i want returning. 

The data below is not in table form in the log file, its just text.  

 

NAME READY STATUS RESTARTS AGE

Process1 2/2 Running 0 8d

Process2ab  2/2 Running 0 8d

Process 3abc  1/3 Running 0 8d

 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

There probably are a few ways to do that.  Here's one.

<<your search>>
| rex "\s(?<a>\d+)\/(?<b>\d+)"
| where a!=b
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...