Hi All,
I am new to splunk and need help in creating a table to get max value.
Below are my sample logs -
2017-05-25 14:21:06,757 INFO [http-/x.x.x.x.x:] [blablaServiceImpl] [myservices()][blablablablabla] [blablablablabla] [TOTAL_TIME_TAKEN][181]
Kindly help getting a table where max value of TOTAL_TIME_TAKEN will be displayed in (tabular foramat) per service
Like this:
Your Base Search Here
| rex "^([^\]]+\]){2}\s*\[(?<service>.*?)\(\)\]([^\]]+\]){2}\s*\[TOTAL_TIME_TAKEN\]\s*\[(?<TOTAL_TIME_TAKEN>\d+)"
| stats max(TOTAL_TIME_TAKEN) BY service
if you have lets say 181 extracted as a value of TOTAL_TIME_TAKEN
... | stats max(TOTAL_TIME_TAKEN) by service ?
or... full solution by @woodcock