ELB parsing specific field values

Comments

2 comments

  • Avatar
    Olaf Stein

    Ben,

    you should be able to do just a count, without the group by. I also moved the where clause up for efficiency purposes:

    _sourceCategory = "<sourceName>" 
    | parse "* * * * * * * * * * * \"*\" \"*\" * *" as datetime, ELB_Server, client, backend, request_processing_time, backend_processing_time, response_processing_time, elb_status_code, backend_status_code, received_bytes, sent_bytes, request,user_agent,ssl_cipher,ssl_protocol
    | where ELB_Server matches "ELB-number1" or ELB_Server matches "ELB-number2"
    | parse field=request "* *://*:*/* HTTP" as method, protocol, domain, server_port, path nodrop
    | parse field=client "*:*" as clientIP, port nodrop
    | parse field=backend "*:*" as backendIP, backend_port nodrop
    | fields - request, client, backend
    // Parse all fields above, then aggregate
    | count
    | sort _count
    1
    Comment actions Permalink
  • Avatar
    Ben Adlard

    That did the trick.

    Many thanks Olaf

    0
    Comment actions Permalink

Please sign in to leave a comment.