Splunk Search

Get the number from the log with ":" Symbol

karthi25
Path Finder

I have a log which looks like follows:

||pool-2-thread-1|| INFO  com.tmobile.sfdc.reports.service.OpportunityService - OPPORTUNITY_JOB: List size: 41 

||pool-2-thread-1|| INFO  com.tmobile.sfdc.reports.service.OpportunityService - OPPORTUNITY_JOB: List size: 140

I want to get the sum of the numbers(140+41+..), And I have tried the below query

base search| rex field=_raw "List size\"\:\"(?<size>[^\"]+)" | stats sum(size)

But it returns nothing. Can anyone please suggest me what am doing wrong.

0 Karma
1 Solution

elliotproebstel
Champion

How about this:

base search
| rex field=_raw "List size:\s(?<size>\d+)"
| stats sum(size)

Here's a working demo based on your data above:
https://regex101.com/r/LifiVU/1/

View solution in original post

elliotproebstel
Champion

How about this:

base search
| rex field=_raw "List size:\s(?<size>\d+)"
| stats sum(size)

Here's a working demo based on your data above:
https://regex101.com/r/LifiVU/1/

karthi25
Path Finder

@elliotproebstel how can change the above query if it is the date. For eg: if I contains the log like
||pool-2-thread-1|| INFO com.tmobile.sfdc.reports.batch.listener.OrderJobListener - ORDER_JOB: ACTIVE at START_TIME: 2018-05-07T06:04:46.087Z

and I want to get the value "2018-05-07T06:04:46.087Z"

0 Karma

elliotproebstel
Champion

How about this:

base search
| rex field=_raw "(?<date>[^ ]+$)"

Here's a demo:
https://regex101.com/r/Y06SsX/1

This regex is collecting everything between the last space and the end of the line and assigning it to a field called date.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...