HI,
i have logs written by Tomcat application
i have a table which displays time, environment, applicationame, and log info details. These are displayed based on drop-down values.
but if i want to search for particular search term like error, exception, out of memory, oserror and more, I need to pass these search terms dynamically. is there a query we can write for this?
You need to use tokens in your SPL to filter based on user entry. Here's some documentation to get you started
http://docs.splunk.com/Documentation/Splunk/6.5.1/Viz/tokens#Define_tokens_for_form_inputs
You need to use tokens in your SPL to filter based on user entry. Here's some documentation to get you started
http://docs.splunk.com/Documentation/Splunk/6.5.1/Viz/tokens#Define_tokens_for_form_inputs
Thank you,i am going through the document.
some how i am not seeing Accept button.any idea on this. or
is there any issue from my side
Yes,i see it now. and i just implemented Token in SPL and its working now.
may i know what is the issue with Accept button
At first, I had posted as a comment. Comments don't have accept. Then I changed to answer.
Hi,
will i get both error info and events i search like below
index=myindex java.lang.stringindexoutofboundsexception OR out of memory
i think this is working,i just tested
index=myindex java.lang.stringindexoutofboundsexception OR (out of memory)
You should see the accept button now.