Hi
This is my current Splunk search:
index=pqaestore source="/log/jboss_jmx_stats.log" | dedup host | rex field=_raw "(?memory=(?\d+))" | rex field=_raw "(?httpthreads=(?\d+))" | rex field=_raw "(?httpsthreads=(?\d+))" | rex field=_raw "(?websessions=(?\d+))" | rex field=_raw "(?ATGAdminDS=(?\d+))" | rex field=_raw "(?ATGCatalogDSA=(?\d+))" | rex field=_raw "(?ATGCatalogDSB=(?\d+))" | rex field=_raw "(?ATGCSCAdminDS=(?\d+))" | rex field=_raw "(?ATGCustDS=(?\d+))" | rex field=_raw "(?ATGOrderDS=(?\d+))" | rex field=_raw "(?ATGPriceDS=(?\d+))" | rex field=_raw "(?ATGSearchDS=(?\d+))" | rex field=_raw "(?DefaultDS=(?\d+))" | rex field=_raw "(?EStoreAdmDS=(?\d+))" | streamstats count as SNo| table SNo host FreeMemory httpthreads httpsthreads websessions ATGAdminDS ATGCatalogDSA ATGCatalogDSB ATGCSCAdminDS ATGCustDS ATGOrderDS ATGPriceDS ATGSearchDS DefaultDS EStoreAdmDS
Table output [Removed the host from output as it is sensitive]
FreeMemory httpthreads httpsthreads websessions ATGAdminDS ATGCatalogDSA
54 0 0 11 2 2 2 0 5 7 0 0
40 0 0 12 2 2 2 2 5 7 2 0
51 0 0 11 2 2 2 0 5 7 0 0
51 0 0 10 2 2 2 0 5 7 0 0
56 1 0 12 2 2 2 0 5 7 0 0
55 1 0 11 2 2 2 0 5 7 0 0
78 0 0 8 2 2 2 0 5 7 0 0
70 0 0 9 2 2 2 0 5 7 0 0
65 0 0 11 2 2 2 0 5 7 2 0
50 1 0 10 2 2 2 0 5 7 0 0
60 1 0 9 2 2 2 0 5 7 0 0
52 0 0 10 2 2 2 0 5 7 0 0
How to print Total, min, Max, Average at the end of this table as separate rows. Please advise.
↧