I have a data set as such:
id=20121,name=jack,score=60,difficulty= French written exam- LEVEL:hard,class 232
id=20121,name=steve,score=23,difficulty=French written exam-LEVEL:medium,class 234
I wish to count the amount of hard exams and medium exams, i know this seems simple and i have tried with rex fieldname=examtype("hard) but i don't know how to count the occurances of each in one search.
If you have a field extracted for the class level then you could do this:
<your search> | stats count by class_level
Use the interactive field extractor to create the class_level field for you or whatever you want to call it. The link below will walk you through it in the docs.
http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/ExtractfieldsinteractivelywithIFX
If you have a field extracted for the class level then you could do this:
<your search> | stats count by class_level
Use the interactive field extractor to create the class_level field for you or whatever you want to call it. The link below will walk you through it in the docs.
http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/ExtractfieldsinteractivelywithIFX
Glad to help
Thanks for your answer it provided me with the exact regex i required to count each value! Thanks!