| server_state=RUNNING | server_health=Component:ServerRuntime , State:HEALTH_OK , MBean:managed2, ReasonCode:[]
this is the snippet that i need to get the state from
I am a beginner in splunk
Try
|rex field=<your filedname> "State:(?<State>.+?),"
Test
|makeresults|eval text="| server_state=RUNNING | server_health=Component:ServerRuntime , State:HEALTH_OK , MBean:managed2, ReasonCode:[]"
|rex field=text "State:(?<State>.+?),"
Try
|rex field=<your filedname> "State:(?<State>.+?),"
Test
|makeresults|eval text="| server_state=RUNNING | server_health=Component:ServerRuntime , State:HEALTH_OK , MBean:managed2, ReasonCode:[]"
|rex field=text "State:(?<State>.+?),"
I need to extract the field and add it to a table
see here
`index_wls` server=* server_state=* domain=* server_health=* | dedup host,server | table host,server ,server_state,
now from the State I want to add a Row Status to my table to be like
`index_wls` server=* server_state=* domain=* server_health=* | dedup host,server | table host,server ,server_state, Status