Splunk Search

Can you help me pull a number and then show that value in a timechart?

orchapellico
Explorer
2018-09-20T11:48:41.071-0600 I NETWORK  [conn16918] end connection 10.16.33.19:61051 (28 connections now open)

So I need to be able to capture the value "28" that is in the (28 connections now open), use that as a value and chart based on host. Thank you!

Tags (2)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@orchapellico

Can you please try following search?

index=YOUR_INDEX | rex field=_raw "\((?<CONNECTIONS>\d+)\sconnections\snow\sopen\)" | timechart sum(CONNECTIONS) as total_connections by host

Here I have use sum() to get total_connections count.

Thanks

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...