I have a working snmp log file which I can search and email the data "anomosied" successfuly now however it i emailing all the contents of the file that match the search not simple the latest one / two of interest, I could using Redhat to logrotate, however is there anyway within Splunk to get just the top X matches or such? I would like to keep all the data at the moment.
Thank you in advance Anthony
Thank you that looks spot on, I will try on monday (thank you.)
I think you need to clarify what you want to do. If you just want the latest X matches, there's the head
command that you could use:
... | head X