<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Query in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447672#M55067</link>
    <description>&lt;P&gt;Is this the sort of thing that would do what you want:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://app.box.com/s/cfbqgucsqwaaj1zznbqcrlj6hjpi6dqs" alt="alt text" /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jun 2018 22:44:30 GMT</pubDate>
    <dc:creator>cpetterborg</dc:creator>
    <dc:date>2018-06-13T22:44:30Z</dc:date>
    <item>
      <title>Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447663#M55058</link>
      <description>&lt;P&gt;Hi Team, &lt;/P&gt;

&lt;P&gt;I have a challenge here, i totally have no idea to design this query, Please help in doing this.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Test Data :&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Line Number 1&lt;/STRONG&gt; =&amp;gt; 2017-08-08 22:38:24,331 INFO &lt;A href="https://community.splunk.com/httpXYSGHFA%2010.100.1234.12-1234-81" target="_blank"&gt;XYZXYZ&lt;/A&gt; 22:38:24,331 INFO [APP_INVOKE_MSG] APP Request [ ID_01SDFBH//-1/NO,RULE.ID:1:1=below minimum value (0) ]&lt;BR /&gt;
&lt;STRONG&gt;Line Number 2&lt;/STRONG&gt; =&amp;gt; 2017-08-08 22:39:45,331 WARN &lt;A href="https://community.splunk.com/httpXYSGHFA%2010.100.1234.12-1234-11" target="_blank"&gt;XYZXYZ&lt;/A&gt; 22:38:24,331 INFO [APP_INVOKE_MSG] APP Request [ ID_02SDFBH//-1/NO,RULE.ID:1:1=below minimum value (0) ]&lt;BR /&gt;
&lt;STRONG&gt;Line Number 3&lt;/STRONG&gt; =&amp;gt; 2017-08-08 22:42:57,331 ERROR &lt;A href="https://community.splunk.com/httpXYSGHFA%2010.100.1234.12-1234-81" target="_blank"&gt;XYZXYZ&lt;/A&gt; 22:38:24,331 INFO [APP_INVOKE_MSG]  [ ID_34SDFBH//-1/NO,RULE.ID:1:1=below minimum value (0) ]&lt;BR /&gt;
&lt;STRONG&gt;Line Number 4&lt;/STRONG&gt; =&amp;gt; 2017-08-08 22:48:24,331 SEVIER &lt;A href="https://community.splunk.com/httpXYSGHFA%2010.100.1234.12-1234-81" target="_blank"&gt;XYZXYZ&lt;/A&gt; 22:38:24,331 INFO [APP_INVOKE_MSG]  [ ID_23SDFBH//1/NO,RULE.ID:1:1=below minimum value (0) ]&lt;BR /&gt;
&lt;STRONG&gt;Line Number 5&lt;/STRONG&gt; =&amp;gt; 2017-08-08 22:55:23,331 INFO &lt;A href="https://community.splunk.com/httpXYSGHFA%2010.100.1234.12-1234-12" target="_blank"&gt;XYZXYZ&lt;/A&gt; 22:38:24,331 INFO [APP_INVOKE_MSG]  [ //-1/NO,RULE.ID:1:1=below minimum value (0) ]&lt;BR /&gt;
&lt;STRONG&gt;Line Number 6&lt;/STRONG&gt; =&amp;gt; 2017-08-08 22:58:32,331 INFO &lt;A href="https://community.splunk.com/httpXYSGHFA%2010.100.1234.12-1234-81" target="_blank"&gt;XYZXYZ&lt;/A&gt; 22:38:24,331 INFO [APP_INVOKE_MSG] APP Request [ ID_32SDFBH//-1/NO,RULE.ID:1:1=below minimum value (0) ]&lt;BR /&gt;
&lt;STRONG&gt;Line Number 7&lt;/STRONG&gt; =&amp;gt; 2017-08-08 23:01:42,331 ERROR &lt;A href="https://community.splunk.com/httpXYSGHFA%2010.100.1234.12-1234-33" target="_blank"&gt;XYZXYZ&lt;/A&gt; 22:38:24,331 INFO [APP_INVOKE_MSG] APP Request [ ID_01SDFBH//-1/NO,RULE.ID:1:1=below minimum value (0) ]&lt;BR /&gt;
&lt;STRONG&gt;Line Number 8&lt;/STRONG&gt; =&amp;gt; 2017-08-08 22:38:34,331 INFO &lt;A href="https://community.splunk.com/httpXYSGHFA%2010.100.1234.12-1234-81" target="_blank"&gt;XYZXYZ&lt;/A&gt; 22:38:24,331 INFO [APP_INVOKE_MSG] APP Request [ ID_02SDFBH//-1/NO,RULE.ID:1:1=below minimum value (0) ]&lt;BR /&gt;
&lt;STRONG&gt;Line Number 9&lt;/STRONG&gt; =&amp;gt; 2017-08-08 22:38:25,331 INFO &lt;A href="https://community.splunk.com/httpXYSGHFA%2010.100.1234.12-1234-23" target="_blank"&gt;XYZXYZ&lt;/A&gt; 22:38:24,331 INFO [APP_INVOKE_MSG] APP Response [ ID_23SDFBH//-1/NO,RULE.ID:1:1=below minimum value (0) ]&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Data Parsing Formate:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Timestamp :&lt;/STRONG&gt; 2017-08-08 22:38:24&lt;BR /&gt;
&lt;STRONG&gt;Logging_Priority :&lt;/STRONG&gt; 331 &lt;BR /&gt;
&lt;STRONG&gt;Log_Level :&lt;/STRONG&gt; INFO &lt;BR /&gt;
&lt;STRONG&gt;Connection_factory :&lt;/STRONG&gt; [XYZXYZ] &lt;BR /&gt;
&lt;STRONG&gt;Thread_Number :&lt;/STRONG&gt; (httpXYSGHFA 10.100.1234.12-1234-81) &lt;BR /&gt;
&lt;STRONG&gt;Application_Message :&lt;/STRONG&gt; 22:38:24,331 INFO [APP_INVOKE_MSG] APP Response [ ID_123SDFBH//-1/NO,RULE.ID:1:1=below minimum value (0) ]&lt;/P&gt;

&lt;P&gt;In the Above set of test data, i wanna write a query in the way it should meet the following needs &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Case 1:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;If we are searching for the CUS_ID = ID_01SDFBH (This id will be in the 1st line of the test data in the Application_Message field)&lt;BR /&gt;
Splunk should take the the thread number (here it should take "httpXYSGHFA 10.100.1234.12-1234-81" &amp;amp; "httpXYSGHFA 10.100.1234.12-1234-33")&lt;BR /&gt;
&lt;STRONG&gt;Example Using Test Data&lt;/STRONG&gt;&lt;BR /&gt;
Here the splink should display the Thread Number's in line Number 1 &amp;amp; 7 because as the log line contain the Search test which is CUS_ID = ID_01SDFBH&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/251883-dashboard.jpg" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Case 2:&lt;/STRONG&gt;&lt;BR /&gt;
When I choose the thread ID "httpXYSGHFA 10.100.1234.12-1234-81" splunk should return the log lines between the next occurrence of the (Same Thread Number)"httpXYSGHFA 10.100.1234.12-1234-81" &amp;amp; String "APP Request"&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Example Using Test Data&lt;/STRONG&gt; &lt;BR /&gt;
Here the splunk should display from the Line 1 to Line 5 as the line 1 has the CUS_ID = ID_01SDFBH + "APP Request" + Thread Number="httpXYSGHFA 10.100.1234.12-1234-81", And ends at the line 5 as the line 6 has Same Threads  Number "httpXYSGHFA 10.100.1234.12-1234-81" &amp;amp; "APP Request"&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/251884-drill-down-dashboard.jpg" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:55:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447663#M55058</guid>
      <dc:creator>Vigneshprasanna</dc:creator>
      <dc:date>2020-09-29T19:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447664#M55059</link>
      <description>&lt;P&gt;Are any fields being extracted in this or do we need to start there?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 13:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447664#M55059</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2018-06-06T13:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447665#M55060</link>
      <description>&lt;P&gt;So I started working through extractions (for reference included below) but quickly realized I don't understand the scope of this question.&lt;/P&gt;

&lt;P&gt;1) Do you have extractions for the fields you are trying to use already?&lt;BR /&gt;
2) Where did that "Test data" come from - that looks like a spreadsheet so it was manually done?&lt;BR /&gt;
3) And what's the flow here?  It seems this is really a problem with dashboard drill-downs, is that right?  &lt;/P&gt;

&lt;P&gt;If number 3 is really the issue, well, we have to walk before we run by defining fields and getting searches that make happen what you want to have happen.  After you get that sorted out, then dashboard building is just linking those various pieces we've created together and is relatively simple.&lt;/P&gt;

&lt;P&gt;But you didn't tell us how to extract fields from the "Application Message".  Do you think the only field you need in there is the CUS_ID, and CUS_ID is the test between that one &lt;CODE&gt;[&lt;/CODE&gt; and the following &lt;CODE&gt;/&lt;/CODE&gt;, does that sound right?  And for completeness sake, Application_Message appears to be  regular enough we can likely just extract all the pieces easily enough, so if you have a definition for those fields that you'd like to use and could pass that along, I think that would be useful.&lt;/P&gt;

&lt;P&gt;Your case 2: probably just a group by clause, but I think first off we need to straight out field extractions and the various searches we'll need for case 1, then I think case 2 may be pretty simple.  (See comments about not getting ahead of ourselves).&lt;/P&gt;

&lt;P&gt;I think this is all not terribly difficult to do, but there's a lot of pieces that seem all tangled up together.  Could you clarify those questions above?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex ",(?&amp;lt;Logging_Priority&amp;gt;\d+)\s+(?&amp;lt;Log_Level&amp;gt;\w+)\s+\[(?&amp;lt;Connection_factory&amp;gt;[^]]*)\]\s\((?&amp;lt;thread_id&amp;gt;[^)]*)\)(?&amp;lt;Application_Message&amp;gt;.*)"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:55:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447665#M55060</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2020-09-29T19:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447666#M55061</link>
      <description>&lt;P&gt;Hi Rich, &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Im pulling in the log data from an application log folder, and have already extracted in the above given "Data Parsing Formate: "
For better understanding im providing a log and its regx &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Log : &lt;BR /&gt;
This shows you one request and response &lt;/P&gt;

&lt;P&gt;2018-05-14 14:00:00,204 INFO  &lt;A href="https://community.splunk.com/http-Applicationserver%10.10.10.100.100-8080-5"&gt;STDOUT&lt;/A&gt; 14:00:00,204 [domain:name:application:invoke] INFO - APP Request [ app.ico.SELECT,,***********//TN599qerqi839,RT1.call.ads,@ID:EQ=TN599qerqi839 ]&lt;/P&gt;

&lt;P&gt;2018-05-14 14:00:00,236 INFO  &lt;A href="https://community.splunk.com/http-Applicationserver%10.10.10.100.100-8080-5"&gt;STDOUT&lt;/A&gt; 14:00:00,236 [domain:name:application:invoke] INFO - APP Response [ ,,"   20171214" ]&lt;/P&gt;

&lt;P&gt;Regax :&lt;BR /&gt;
^(?P[^,]+)[^,\n]*,(?P\d+)\s+(?P\w+)\s+(?P[^ ]+)\s+(?P[^ ]+)\s+(?P.+)&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;The data is not coming from a spreed sheet its from a .log file we generally open it in note pad.&lt;/LI&gt;
&lt;LI&gt;Yes, its a folw from a dashboard to drill down. &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Application MSG is a field that is not defined properly that contains the data generated by the application , as we are not maintaining the session id we are not able to tract the request and response of a specific request so the idea is that the thread number generated at the time of request will flow until the response or error is thrown, using this i know the value customer ID  i will use it to get the logs having the customer id and "- APP Request " &lt;BR /&gt;
for example if i want session logs of id 1445&lt;/P&gt;

&lt;P&gt;i will search for &lt;STRONG&gt;index=* Application_MSG ="&lt;EM&gt;1445&lt;/EM&gt;" and " - APP Request"&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;so the above query will list me the logs  contains index=* Application_MSG ="&lt;EM&gt;1445&lt;/EM&gt;" and " - APP Request"&lt;BR /&gt;
from the logs i need to take the thread ID and have a drop down &lt;/P&gt;

&lt;P&gt;in that drop down if i select an thread number (for example if im selecting  : http-Applicationserver%10.10.10.100.100-8080-5) it should return all the logs between this thread number and the next occurrence of the same thread number thread number &amp;amp; " - APP Request"(for the above example it will be like i should list the logs in between the until i get the next log having the same thread number "http-Applicationserver%10.10.10.100.100-8080-5" &amp;amp; "- APP Request " )&lt;/P&gt;

&lt;P&gt;to term it simple i should list all the logs in between log congaing thread number "http-Applicationserver%10.10.10.100.100-8080-5 " &amp;amp; "- APP Request" to "http-Applicationserver%10.10.10.100.100-8080-5 " &amp;amp; "- APP Request"&lt;/P&gt;

&lt;P&gt;for selecting the thread number "http-Applicationserver%10.10.10.100.100-8080-5" only  we are using some ID in the application MSG "1445"(this can vary)&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 16:08:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447666#M55061</guid>
      <dc:creator>Vigneshprasanna</dc:creator>
      <dc:date>2018-06-06T16:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447667#M55062</link>
      <description>&lt;P&gt;@rich7177 do you have any idea on this ??&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 17:32:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447667#M55062</guid>
      <dc:creator>Vigneshprasanna</dc:creator>
      <dc:date>2018-06-12T17:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447668#M55063</link>
      <description>&lt;P&gt;The &lt;CODE&gt;Regax&lt;/CODE&gt; that you used above (Regex) doesn't have the names in it. Can you provide the data again, but this time use the "code" button (101010) to format the data properly to give all the information. There may be some other data that is missing that we don't even know about that may be in this same situation. This will aid us in answering your question.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 22:59:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447668#M55063</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2018-06-12T22:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447669#M55064</link>
      <description>&lt;P&gt;From what I have tried, you won't be able to go from a dashboard to a separate drill down page, but you can use the drill down to change a token in the dashboard to allow you to make another dashboard panel use that data to perform it's search and produce the results you would have wanted in the separate drill down page.&lt;/P&gt;

&lt;P&gt;One complication is that you only want to go from the first occurrence of the Thread_Number to the next event with the same Thread_Number AND "- APP Request". It might be possible with a &lt;CODE&gt;transaction&lt;/CODE&gt;. But then you lose the field extractions for making a clean table of data. It is possible to combine the fields, then separate them again, but if that can be avoided, it would be easier.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:54:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447669#M55064</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2020-09-29T19:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447670#M55065</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/120445"&gt;@cpetterborg&lt;/a&gt; &lt;/P&gt;

&lt;P&gt;the above i have provided was jest a sample info, for better understanding i have added some details below hope this will help us .&lt;/P&gt;

&lt;P&gt;or the below sample data &lt;/P&gt;

&lt;P&gt;2018-05-14 14:25:00,093 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-8" target="_blank"&gt;STDOUT&lt;/A&gt; 14:25:00,093 [com.xxxxxxx.xxx.conn.aoo.invok] INFO - APP Request [ eq.SELECT,,***********//DTA,AA.AA.AA.AAAA,@ID:EQ=DTA ]&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.beans.xxxxxxxBean&lt;/A&gt; Transform - Completed server response transform. Took 31 ms.&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.servlets.BrowserServlet&lt;/A&gt; 123-132-0-23-0&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.servlets.BrowserServlet&lt;/A&gt; &lt;BR /&gt;
2018-05-14 14:25:00,171 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-8" target="_blank"&gt;STDOUT&lt;/A&gt; 14:25:00,171 [com.xxxxxxx.xxx.conn.aoo.invok] INFO - APP Request [ ,,"   123145353" ]&lt;BR /&gt;
2018-05-14 14:25:00,296 WARN  &lt;A href="http-xxxxxx%xx.123.123.123-800-2" target="_blank"&gt;org.apache.tomcat.util.http.Parameters&lt;/A&gt; Parameters: Invalid chunk ignored.&lt;BR /&gt;
2018-05-14 14:25:00,311 WARN  &lt;A href="http-xxxxxx%xx.123.123.123-800-6" target="_blank"&gt;org.apache.tomcat.util.http.Parameters&lt;/A&gt; Parameters: Invalid chunk ignored.&lt;/P&gt;

&lt;P&gt;and the above sample data is parses as &lt;BR /&gt;
Fields&lt;BR /&gt;
AUDIT_TIME,LOGGING_PRIORITY,LOG_LEVEL,THREAD_NUMBER ,CONNECTION_FACTOR,AUDIT_DATA&lt;BR /&gt;
Regular Expression&lt;BR /&gt;
^(?P[^,]+),(?P\d+)\s+(?P\w+)\s+(?P[^ ]+)\s+(?P[^ ]+)\s(?P.+)&lt;/P&gt;

&lt;P&gt;In the above data i have mapped THREADNUMBER :"http-xxxxxx%xx.123.123.123-800-8" As value A and AUDIT_DATA: "APP Request" as value B &lt;/P&gt;

&lt;P&gt;so now im trying to print the below events as they are the values between the same values combinationa of A &amp;amp; B &lt;/P&gt;

&lt;P&gt;2018-05-14 14:25:00,093 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-8" target="_blank"&gt;STDOUT&lt;/A&gt; 14:25:00,093 [com.xxxxxxx.xxx.conn.aoo.invok] INFO - APP Request [ eq.SELECT,,***********//DTA,AA.AA.AA.AAAA,@ID:EQ=DTA ]&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.beans.xxxxxxxBean&lt;/A&gt; Transform - Completed server response transform. Took 31 ms.&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.servlets.BrowserServlet&lt;/A&gt; 123-132-0-23-0&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.servlets.BrowserServlet&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Regards, &lt;BR /&gt;
Vigneshprasanna R &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:58:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447670#M55065</guid>
      <dc:creator>Vigneshprasanna</dc:creator>
      <dc:date>2020-09-29T19:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447671#M55066</link>
      <description>&lt;P&gt;Hi cpetterborg , &lt;/P&gt;

&lt;P&gt;Hope the below info can help us to understand &lt;/P&gt;

&lt;P&gt;for the below sample data &lt;/P&gt;

&lt;P&gt;2018-05-14 14:25:00,093 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-8" target="_blank"&gt;STDOUT&lt;/A&gt; 14:25:00,093 [com.xxxxxxx.xxx.conn.aoo.invok] INFO - APP Request [ eq.SELECT,,***********//DTA,AA.AA.AA.AAAA,@ID:EQ=DTA ]&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.beans.xxxxxxxBean&lt;/A&gt; Transform - Completed server response transform. Took 31 ms.&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.servlets.BrowserServlet&lt;/A&gt; 123-132-0-23-0&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.servlets.BrowserServlet&lt;/A&gt; &lt;BR /&gt;
2018-05-14 14:25:00,171 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-8" target="_blank"&gt;STDOUT&lt;/A&gt; 14:25:00,171 [com.xxxxxxx.xxx.conn.aoo.invok] INFO - APP Request [ ,,"   123145353" ]&lt;BR /&gt;
2018-05-14 14:25:00,296 WARN  &lt;A href="http-xxxxxx%xx.123.123.123-800-2" target="_blank"&gt;org.apache.tomcat.util.http.Parameters&lt;/A&gt; Parameters: Invalid chunk ignored.&lt;BR /&gt;
2018-05-14 14:25:00,311 WARN  &lt;A href="http-xxxxxx%xx.123.123.123-800-6" target="_blank"&gt;org.apache.tomcat.util.http.Parameters&lt;/A&gt; Parameters: Invalid chunk ignored.&lt;/P&gt;

&lt;P&gt;and the above sample data is parses as &lt;BR /&gt;
Fields&lt;BR /&gt;
AUDIT_TIME,LOGGING_PRIORITY,LOG_LEVEL,THREAD_NUMBER ,CONNECTION_FACTOR,AUDIT_DATA&lt;BR /&gt;
Regular Expression&lt;BR /&gt;
^(?P[^,]+)[^,\n]*,(?P\d+)\s+(?P\w+)\s+(?P[^ ]+)\s+(?P[^ ]+)\s+(?P.+)&lt;/P&gt;

&lt;P&gt;In the above data i have mapped THREADNUMBER :"http-xxxxxx%xx.123.123.123-800-8" As value A and AUDIT_DATA: "APP Request" as value B &lt;/P&gt;

&lt;P&gt;so now im trying to print the below events as they are the values between the same values combinationa of A &amp;amp; B &lt;/P&gt;

&lt;P&gt;2018-05-14 14:25:00,093 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-8" target="_blank"&gt;STDOUT&lt;/A&gt; 14:25:00,093 [com.xxxxxxx.xxx.conn.aoo.invok] INFO - APP Request [ eq.SELECT,,***********//DTA,AA.AA.AA.AAAA,@ID:EQ=DTA ]&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.beans.xxxxxxxBean&lt;/A&gt; Transform - Completed server response transform. Took 31 ms.&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.servlets.BrowserServlet&lt;/A&gt; 123-132-0-23-0&lt;BR /&gt;
2018-05-14 14:25:00,108 INFO  &lt;A href="http-xxxxxx%xx.123.123.123-800-3" target="_blank"&gt;com.xxxxxxx.browser.servlets.BrowserServlet&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:59:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447671#M55066</guid>
      <dc:creator>Vigneshprasanna</dc:creator>
      <dc:date>2020-09-29T19:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447672#M55067</link>
      <description>&lt;P&gt;Is this the sort of thing that would do what you want:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://app.box.com/s/cfbqgucsqwaaj1zznbqcrlj6hjpi6dqs" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 22:44:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447672#M55067</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2018-06-13T22:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447673#M55068</link>
      <description>&lt;P&gt;Hi  cpetterborg, &lt;BR /&gt;
No I’m not looking for all text &lt;span class="lia-unicode-emoji" title=":frowning_face:"&gt;☹️&lt;/span&gt;. &lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 00:49:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447673#M55068</guid>
      <dc:creator>Vigneshprasanna</dc:creator>
      <dc:date>2018-06-14T00:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447674#M55069</link>
      <description>&lt;P&gt;Okay. Good luck then.  I don't know where to go with this at this point. Perhaps someone else will have some idea of where to go with an answer.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 20:16:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447674#M55069</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2018-06-14T20:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447675#M55070</link>
      <description>&lt;P&gt;....| rex field=_raw "(?\d+-\d+-\d+\s+\d+:\d+).&lt;EM&gt;[xyzxyz]\s+((?.&lt;/EM&gt;))\s+.*"&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 07:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Query/m-p/447675#M55070</guid>
      <dc:creator>arihant16cse</dc:creator>
      <dc:date>2019-02-06T07:28:45Z</dc:date>
    </item>
  </channel>
</rss>

