Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Extracting simple array of strings

$
0
0
I have a simple entry in my logs like so: types=["A","B","C"] There are several entries like that throughout the logs. Another one could look like this: types=["B","C"] Is there a way to extract the values from this array of strings and create a bar chart out of the occurrences of each type? So if splunk only saw the above 2 long entries it would make a bar chart with - "# of occurrences" on the y-axis - "Types" on the x-axis And it would show 1 for type A, 2 for type B and C. What would be the search criterion?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>