Splunk Search

Put results in one row table

lgroot
Explorer

Hello,

I have got a question about a Query. This is the query:

index=security-mijnssp "View rendered = /error.jspx" OR "Er is een fout opgetreden op de JSF"  | rex "BSN=(?P<BSN>[^<]+) View" | rex "INFO  n.s.m.w.l(?P<INFO>[^<]+)"|rex "ERROR n.s.m.w.l(?P<ERROR>[^<]+)"|  table BSN, INFO, ERROR, _time

And this is how the table look likes:

alt text

My question is how i can put the results in one row? So that BSN, INFO, ERROR and Time are on the same line sorted by Time?

Thanks for the answer!

Tags (2)
0 Karma

grijhwani
Motivator

Look at the documentation for transactions, and use BSN as your transaction identifier.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...