I try to create a vizualisation with Timelion with dynamic labels ( extracted from request response )
For example: the following search in Discover tools
message: "SQL ERROR"
results in following response:
SQL ERROR occurs in DATABASE ORACLE_DFS01 at 15:01
SQL ERROR occurs in DATABASE ORACLE_DFS02 at 17:05
SQL ERROR occurs in DATABASE ORACLE_DFS01 at 19:01
SQL ERROR occurs in DATABASE ORACLE_DFS03 at 20:01
I would like to create a vizualization in which i would count all SQL ERRORS for each database:
I would proceed as follow to extract dynamically the label from the result:
.es(q='message: "SQL ERROR"', index=ref_rfnd*).label("$1", " DATABASE\s([a-zA-Z0-9._-]+)")
But it did not work
Can you help me ?