如何提取splunk中的字段值

时间:2019-10-15 16:19:21

标签: splunk

如何使用rex field = _raw提取Splunk中的字段值

logAlias=Overall|logDurationMillis=1298|logTimeStart=2019-10-15_00:01:12.821|logTimeStop=2019-10-15_00:01:14.119|UniqueId=8aa984556db09592016dcd93b5a708ee

路径:/ var / opt / pivotal / logs 日志文件:file.log

Splunk查询:

index=main source="/var/opt/pivotal/logs/file.log*" | rex field=_raw "logDurationMillis= (?<numbr>\d+)" | where numbr>950 | stats count(numbr) As FailedFraudAPITxns

0 个答案:

没有答案