We have a message in logs which prints based on values sent in request.
Ex in logs :
"service-1 requested with type - 1"
"service-1 requested with type - 2"
"service-1 requested with type - 3"
Here numeric value after "- (hyphen)" changes based on request. I wanted to find out a requests count based on different numeric values.
Please help me with my Slunk query to get the chart based on time (timechart).
try this - |rex field=_raw "-(?<value>.*)\s+" | chart count by value