2018-09-20T11:48:41.071-0600 I NETWORK [conn16918] end connection 10.16.33.19:61051 (28 connections now open)
So I need to be able to capture the value "28" that is in the (28 connections now open), use that as a value and chart based on host. Thank you!
@orchapellico
Can you please try following search?
index=YOUR_INDEX | rex field=_raw "\((?<CONNECTIONS>\d+)\sconnections\snow\sopen\)" | timechart sum(CONNECTIONS) as total_connections by host
Here I have use sum()
to get total_connections count.
Thanks