问题的一部分是regex字符串,它与示例数据不匹配。另一个问题是不必要的
timechart
命令,它过滤掉“success\u status\u message”字段。尝试此搜索:
(index="05c48b55-c9aa-4743-aa4b-c0ec618691dd" ("Retry connecting in 1000ms ..." OR "Connect or create consumer failed with exception" OR "Connected successfully, creating telemetry consumer ..."))
| rex "\s-\s(?P<success_status_message>.*)"
| eval status=if(match(success_status_message, "Connected successfully, creating telemetry consumer"), 1, 0)