Find centralized, trusted content and collaborate around the technologies you use most.
Teams
Q&A for work
Connect and share knowledge within a single location that is structured and easy to search.
如果我在 Splunk 中得到这条线,
abcd HTTP/1.1 200 0 231 edfg
我怎样才能得到231这个号码?
231
我有很多这样的台词。如何从每行获取数字并根据这些数字绘制图表?谢谢。
| rex field=_raw "HTTP/1.1 \d+ \d+ (?<some_field_name>\d+)" | timechart avg(some_field_name) as Average