Splunk Dev

unstructured logs how to extract the given item example

mindia
New Member

The unsturctured log contains many lines and at the end below coverage report, it is not getting captured as a field, even Extract new field, when I tried, it is adding junk data in the fields covering other lines

line1
line2
..
...
line n
============ coverage report ==========
Statements : 34% (20/22)

Lines : 56% (56/100)

Is it possible to create a search query which would generate the table like

_time Statements Lines
14-9-2018 34% 56%

Since the coverage report is unstructured not able to capture the details as a field.... any suggestions are welcome.

Thanks!.

Tags (1)
0 Karma

493669
Super Champion

Hi @mindia,
you can try this on raw data :

...|rex "Statements : (?<Statements>[^\s+]+).*Lines : (?<Lines>[^\s+]+)"|table _time, Statements , Lines
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...