Splunk Search

How do I fetch a word along with the next five lines in a log and wrap it as an event?

zacksoft
Contributor

My logs are all parsed by time stamps into a new event. Every line in the log starts with a time stamp.

I am searching for the word "tron" and Splunk gives me that line that contains "tron".

But my requirement is:

Whenever I get the line containing "tron" as a search result , I want some SPL magic to fetch that line along with next 5 lines in the log and wrap it as an event in Splunk. I want to achieve this with Splunk Query .

I hope I am clear...

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Try this:

index=foo | transaction startswith="tron" maxevents=6 | ...
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try this:

index=foo | transaction startswith="tron" maxevents=6 | ...
---
If this reply helps you, Karma would be appreciated.
0 Karma

zacksoft
Contributor

@richgalloway ♦
Thank you. This helps.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...