Hi ,
I want a Splunk query to extract and stats count filed from JSON msg body.
For e.g:
index=abc org_name="JBL" AND app_name="contract-rules" AND space_name=Production msg="LoggingService = ContractRule, ContractId, Type = *, Status = Success"|stats count as Success by Src,Type
app_id: 6a878fd5-540e-4a28-b7ae-970e8a91b74e
app_name: contract-rules
org_name: JBL
space_name: Production
message_type: OUT
**msg: 2018-10-04 18:27:38.302 INFO [bill-cntct-rules-v0,57a307b46ae1593b,57a307b46ae1593b,true] 18 --- [nio-8080-exec-4] c.u.f.b.c.service.CntctRuleService : LoggingService = ContractRule, ContractId = H235678, Type = ASC, Src = JBL, Status = Success**
origin: rep
source_instance: 2
source_type: APP/PROC/WEB
timestamp: 1538677658302837000
}
... View more