Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I write a regular expression to extract 2 fields from my sample data?

$
0
0
So I have a search that will check if two variables equal a specific number, and then I get the count of these instances. I am having trouble regexing the numbers I needed to create the variables. index=nitro_prod_ecomm errorCode |rex **(This grabs the Response Code)** | rex **(This grabs Error Code)** | where RespCode = 400 AND ErrorCode = 1001 | table count REQUEST_BODY: {profileId:0156",deviceId:D893-4324234234C"} RESPONSE_CODE:**400** RESPONSE_TIME:2 RESPONSE_HEADERS: Date:Wed, 14 Sep 2016 15:10:17 GMT; X-Powered-By:Servlet/3.0; correlation-id:NAID-iOS-E6B4F6817.94320; channel:IOS; Content-Type:application/json; Transfer-Encoding:chunked; Connection:Close; RESPONSE_BODY: {"errors":[{"errorCode":"**1001**","message":""}]} _WS_HAPRT_WLMVERSION:-1; RESPONSE_CODE:**500** RESPONSE_TIME:11 RESPONSE_HEADERS: X-Powered-By:Servlet/3.0; correlation-id:TID-14743243247; Content-Type:application/json; Transfer-Encoding:chunked; Connection:Close; Date:Wed, 14 Sep 2016 15:33:13 GMT; RESPONSE_BODY: {"errors":[{"errorCode":"**1010**","message":""}]}

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>