Splunk Search

How can I extract specified fields from the log files uploaded in Splunk thru a UI?

tankhanandita
Explorer

I have created a UI which loads the user selected log file in Splunk. Now I have to extract some fields from that file and display that in a table format. How can I do it?
For the UI, I am using jsp and servlets.

0 Karma
1 Solution

woodcock
Esteemed Legend

Just run a search with something like this:

index=YourIndexHere | table YourFieldOne YourFieldTwo

View solution in original post

0 Karma

woodcock
Esteemed Legend

Just run a search with something like this:

index=YourIndexHere | table YourFieldOne YourFieldTwo
0 Karma

tankhanandita
Explorer

Thank you so much for your help. I did the same thing. It was a careless mistake i was trying to wrong fields from the log files.
Again thank u very much.

0 Karma

tankhanandita
Explorer

I have another question.Kindly help on this one also
I have extracted certain feilds using java sdk from splunk with the table command. How can i view that data as a table in my java form.
or
The data extracted is in the form of job. How can i convert that data into string, so that i can apply conditional operators on that data.

Thanks in advance for your help.

0 Karma

woodcock
Esteemed Legend

You are better off clicking Accept on this question and asking a new one. At this point, you and I are probably the only ones listening and you need a broader audience.

0 Karma

tankhanandita
Explorer

But what if my index contains multiple files that have some common fields and i only want to retrieve the data from one file and not all the files?

0 Karma

woodcock
Esteemed Legend

This is basic stuff.

index=YourIndexHere source=MyOneSourceFileHere | table YourFieldOne YourFieldTwo
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...