Sometimes you might need to parse fields that are not well structured within the message. In this example we are counting hits by browser. Since there is no browser field in the message, we simply search for the browser name and store it in its own field for future aggregation.
| if (agent matches "*MSIE*",1,0) as ie
| if (agent matches "*Firefox*",1,0) as firefox
| if (agent matches "*Safari*",1,0) as safari
| if (agent matches "*Chrome*",1,0) as chrome
| sum(ie) as ie, sum(firefox) as firefox, sum(safari) as safari, sum(chrome) as chrome
Please sign in to leave a comment.