Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Regular expression and aggregate the result

$
0
0
Assume the following records: Nov 17 19:24:51 x.x.x.x Nov 17 19:24:51 myserver (appx): 1510943091.801 520 192.168.0.5 CONNECT something else Nov 17 19:24:51 x.x.x.x Nov 17 19:24:51 myserver (appx): 1510943091.801 1040 192.168.0.5 CONNECT something else The above record is a modied squid log and i'd like to get the average response time, in this case it's the value of **520 and 1040** My query: myserver | rex field=_raw "appx\):\s+\d+\.\d+\s+(?

Viewing all articles
Browse latest Browse all 47296

Trending Articles