Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I edit my regular expression for rex to extract all expected fields and values from my sample multiline event?

$
0
0
Here is the logged event: SepsisGraphBuilderImpl: 11252495 MS VitalsGraphBuilderImpl: 2257 MS Mic2GraphBuilder: 358360 MS RasGraphBuilderImpl: 201 MS PatientInfoGraphBuilder: 1992 MS InterventionEventGraphBuilderImpl: 372 MS ObservationInfoGraphBuilder: 42472 MS DrugOrderGraphBuilder: 31849 MS SurgeryAndRadiologyGraphBuilder: 232 MS I am wanting to grab each graphbuilder and the time in MS. I thought this search would work, but I am only getting Mic2GraphBuilder: host=s*gs* *GraphBuilder* | rex field=_raw "(?\w+GraphBuilder*): (?\d+) MS" | table object, totalms

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>