Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

eliminate some value in fields in stats count.

$
0
0
index=* | spath msg.uri | rename msg.uri as url | rex field=url "shop(?[a-zA-Z\/\-0-9\.]+)" | rex field=ex_url "buy-(?[^\/]+)\/(?[^\/]+)" | eval url_N="/shop/"+"buy-"+family +"/" + product +"/" | eval N_url = coalesce(url, url_N) | stats count by N_url | sort -count | head 100 I am trying to find count by URL, but I also need to combine count value that looks like `/shop/buy-phone/LG'. /shop/buy-laptop/Mac` as `/shop/buy-phone/ or /shop/buy-laptop/`. Finally, when I count my URL I need to include these group URLs count with the other URL. I tried above, I am missing something. Thanks for your time.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>