How can I count ids in splunk logs in one line with regex










0














I have log like:
Segment 5bbdf7b8bbdd3c685a2110bf : UserMap is [512205885, 512112460, 512369891, 512316786, 58587803, 506882296]



Segment 5bbdf7b8bbdd3c685a2110bf : UserMap is [514348564, 506722271, 513844106, 513725157]

Segment 5bbdfd69bbdd3c685a21129b : UserMap is [502062935]



I want the stats where I can see number of ids in userMap with respect to the segment. like:



5bbdf7b8bbdd3c685a2110bf - 6



5bbdf7b8bbdd3c685a2110bf - 4



5bbdfd69bbdd3c685a21129b - 1










share|improve this question


























    0














    I have log like:
    Segment 5bbdf7b8bbdd3c685a2110bf : UserMap is [512205885, 512112460, 512369891, 512316786, 58587803, 506882296]



    Segment 5bbdf7b8bbdd3c685a2110bf : UserMap is [514348564, 506722271, 513844106, 513725157]

    Segment 5bbdfd69bbdd3c685a21129b : UserMap is [502062935]



    I want the stats where I can see number of ids in userMap with respect to the segment. like:



    5bbdf7b8bbdd3c685a2110bf - 6



    5bbdf7b8bbdd3c685a2110bf - 4



    5bbdfd69bbdd3c685a21129b - 1










    share|improve this question
























      0












      0








      0







      I have log like:
      Segment 5bbdf7b8bbdd3c685a2110bf : UserMap is [512205885, 512112460, 512369891, 512316786, 58587803, 506882296]



      Segment 5bbdf7b8bbdd3c685a2110bf : UserMap is [514348564, 506722271, 513844106, 513725157]

      Segment 5bbdfd69bbdd3c685a21129b : UserMap is [502062935]



      I want the stats where I can see number of ids in userMap with respect to the segment. like:



      5bbdf7b8bbdd3c685a2110bf - 6



      5bbdf7b8bbdd3c685a2110bf - 4



      5bbdfd69bbdd3c685a21129b - 1










      share|improve this question













      I have log like:
      Segment 5bbdf7b8bbdd3c685a2110bf : UserMap is [512205885, 512112460, 512369891, 512316786, 58587803, 506882296]



      Segment 5bbdf7b8bbdd3c685a2110bf : UserMap is [514348564, 506722271, 513844106, 513725157]

      Segment 5bbdfd69bbdd3c685a21129b : UserMap is [502062935]



      I want the stats where I can see number of ids in userMap with respect to the segment. like:



      5bbdf7b8bbdd3c685a2110bf - 6



      5bbdf7b8bbdd3c685a2110bf - 4



      5bbdfd69bbdd3c685a21129b - 1







      splunk splunk-query






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 11 at 8:54









      Gaurav Yadav

      32




      32






















          1 Answer
          1






          active

          oldest

          votes


















          0














          I think you can't do it all with regex, but this search should get you goingin the right direction.



          <your base search> | rex "Segment (?<Segment>[^:]+)" 
          | rex max_match=0 "UserMap is [(?<id>d+)"
          | idCount=mvcount(id) | table Segment idCount





          share|improve this answer




















          • thank a lot @RichG
            – Gaurav Yadav
            Nov 13 at 6:43










          Your Answer






          StackExchange.ifUsing("editor", function ()
          StackExchange.using("externalEditor", function ()
          StackExchange.using("snippets", function ()
          StackExchange.snippets.init();
          );
          );
          , "code-snippets");

          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "1"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53247181%2fhow-can-i-count-ids-in-splunk-logs-in-one-line-with-regex%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          1 Answer
          1






          active

          oldest

          votes








          1 Answer
          1






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes









          0














          I think you can't do it all with regex, but this search should get you goingin the right direction.



          <your base search> | rex "Segment (?<Segment>[^:]+)" 
          | rex max_match=0 "UserMap is [(?<id>d+)"
          | idCount=mvcount(id) | table Segment idCount





          share|improve this answer




















          • thank a lot @RichG
            – Gaurav Yadav
            Nov 13 at 6:43















          0














          I think you can't do it all with regex, but this search should get you goingin the right direction.



          <your base search> | rex "Segment (?<Segment>[^:]+)" 
          | rex max_match=0 "UserMap is [(?<id>d+)"
          | idCount=mvcount(id) | table Segment idCount





          share|improve this answer




















          • thank a lot @RichG
            – Gaurav Yadav
            Nov 13 at 6:43













          0












          0








          0






          I think you can't do it all with regex, but this search should get you goingin the right direction.



          <your base search> | rex "Segment (?<Segment>[^:]+)" 
          | rex max_match=0 "UserMap is [(?<id>d+)"
          | idCount=mvcount(id) | table Segment idCount





          share|improve this answer












          I think you can't do it all with regex, but this search should get you goingin the right direction.



          <your base search> | rex "Segment (?<Segment>[^:]+)" 
          | rex max_match=0 "UserMap is [(?<id>d+)"
          | idCount=mvcount(id) | table Segment idCount






          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered Nov 11 at 14:40









          RichG

          69148




          69148











          • thank a lot @RichG
            – Gaurav Yadav
            Nov 13 at 6:43
















          • thank a lot @RichG
            – Gaurav Yadav
            Nov 13 at 6:43















          thank a lot @RichG
          – Gaurav Yadav
          Nov 13 at 6:43




          thank a lot @RichG
          – Gaurav Yadav
          Nov 13 at 6:43

















          draft saved

          draft discarded
















































          Thanks for contributing an answer to Stack Overflow!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.





          Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


          Please pay close attention to the following guidance:


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53247181%2fhow-can-i-count-ids-in-splunk-logs-in-one-line-with-regex%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Medaillenspiegel der Olympischen Winterspiele 1968

          Kleinkühnau

          Makov (Slowakei)