Getting Data In

Find line number of search string in multiline event

snoobzilla
Builder

I have multiline events and I need to identify which line number a search string appears in. Preferred would be a solution that avoids breaking entire event into multivalue fields.

e.g. this would return 4
blah blah
blah blah
blah blah
what I want to know line number of
blah blah
blah blah
blah blah

this would return 2
blah blah
what I want to know line number of
blah blah
blah blah
blah blah
blah blah

0 Karma
1 Solution

snoobzilla
Builder

I ended up going with multivalue field solution and mvfind/mvindex solution for this. Expensive but worked.

View solution in original post

0 Karma

snoobzilla
Builder

I ended up going with multivalue field solution and mvfind/mvindex solution for this. Expensive but worked.

0 Karma

alon7786
New Member

Can you publish your solution please

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...