{"id":6324,"date":"2017-06-09T15:08:43","date_gmt":"2017-06-09T20:08:43","guid":{"rendered":"http:\/\/appcrawler.com\/wordpress\/?p=6324"},"modified":"2017-06-09T15:09:03","modified_gmt":"2017-06-09T20:09:03","slug":"splunk-regular-expression-count-by-day","status":"publish","type":"post","link":"http:\/\/appcrawler.com\/wordpress\/2017\/06\/09\/splunk-regular-expression-count-by-day\/","title":{"rendered":"Splunk regular expression count by day"},"content":{"rendered":"<p>This one tripped me up.  The rex command is not a filter, it merely extracts the value where it exists.  As such, you can&#8217;t simply say&#8230;<\/p>\n<pre>\r\nrex field \"(?<myField>mysearch)\" | timechart span=1d count as total\r\n<\/pre>\n<p>&#8230;as this will result in all samples passing and your count being much larger than may be expected.  To use the rex construct, you must sandwich a <code>where myField != \"\"<\/code> between the rex and timechart commands.  For example&#8230;<\/p>\n<pre>\r\nhost=myhost* sourcetype=*server* | rex field=_raw \"(?<restart>Microcontainer.*Started in)\" | where restart != \"\" | timechart span=1d count as restarts_by_day \r\n<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>This one tripped me up. The rex command is not a filter, it merely extracts the value where it exists. As such, you can&#8217;t simply say&#8230; rex field &#8220;(?mysearch)&#8221; | timechart span=1d count as total &#8230;as this will result in&hellip;<\/p>\n<p class=\"more-link-p\"><a class=\"more-link\" href=\"http:\/\/appcrawler.com\/wordpress\/2017\/06\/09\/splunk-regular-expression-count-by-day\/\">Read more &rarr;<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_mi_skip_tracking":false,"footnotes":""},"categories":[81],"tags":[],"_links":{"self":[{"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/posts\/6324"}],"collection":[{"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/comments?post=6324"}],"version-history":[{"count":3,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/posts\/6324\/revisions"}],"predecessor-version":[{"id":6328,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/posts\/6324\/revisions\/6328"}],"wp:attachment":[{"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/media?parent=6324"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/categories?post=6324"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/appcrawler.com\/wordpress\/wp-json\/wp\/v2\/tags?post=6324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}