Are my Collectors ingesting data

Comments

2 comments

  • Avatar
    Training Labs

    i am getting an error while giving these query!!

    Error: "No capture group found in regex, regex=""(?[^"]*)"\:\{"sizeInBytes"\:(?\d+),"count"\:(?\d+)\}". An example of a valid "extract" usage is [extract "From: (?<from>.*) To: (?<to>.*)"]"

    0
    Comment actions Permalink
  • Avatar
    Artur Paprzycki

    Try this:


    _index=sumologic_volume
    | where _sourceCategory="collector_volume"
    | parse regex "\"(?<collector>[^\"]*)\"\:\{\"sizeInBytes\"\:(?<bytes>\d+),\"count\"\:(?<count>\d+)\}" multi
    | timeslice 1h | bytes/1024/1024/1024 as gbytes
    | sum(gbytes) as gbytes by collector, _timeslice
    | where gbytes < 0.00001

    0
    Comment actions Permalink

Please sign in to leave a comment.