<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: query help in splunk cloud in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752064#M3963</link>
    <description>&lt;P&gt;Some of your messages have multiple sequence numbers (ordinals) and some have no sequence number. Try looking at the actual events which are causing you the issue and determine whether the rex needs to be updated to extract the msg field correctly to alleviate this problem&lt;/P&gt;</description>
    <pubDate>Fri, 22 Aug 2025 15:42:40 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2025-08-22T15:42:40Z</dc:date>
    <item>
      <title>query help in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752026#M3958</link>
      <description>&lt;P&gt;&lt;BR /&gt;query is something like :-&lt;BR /&gt;`macro_1` index=abc sequenceNumber=12 `macro_2`&lt;BR /&gt;&lt;BR /&gt;basically the below image had 4 column as&amp;nbsp; and the events following there&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Praz_123_1-1755844648750.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/40025i307CAD3F3C8039DC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Praz_123_1-1755844648750.png" alt="Praz_123_1-1755844648750.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Praz_123_0-1755844591895.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/40024iD306BFB5A2472A7E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Praz_123_0-1755844591895.png" alt="Praz_123_0-1755844591895.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;If we see in the events the logs are missing for the seq no 17 &amp;amp; 24 and time is missing 15,16,17 and 24 also there is 15 and 16 events merge together how will I solve this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 06:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752026#M3958</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2025-08-22T06:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: query help in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752029#M3959</link>
      <description>&lt;P&gt;Your problem appears to be either in macro_1 or macro_2 or both&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 07:07:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752029#M3959</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-08-22T07:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: query help in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752034#M3960</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258639"&gt;@Praz_123&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Without knowing exactly what the two macros are doing its unfortunately impossible for us to know what is going on. Please can you send the expanded version of the search or the contents of the macros?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 08:54:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752034#M3960</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-08-22T08:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: query help in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752043#M3961</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;macro 1:-&lt;BR /&gt;source="/data/splunk/layer7/*"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;macro 2;-&lt;BR /&gt;| rex field=_raw "&amp;lt;detail (?&amp;lt;msg&amp;gt;[\d\D]*?)&amp;lt;/params&amp;gt;&amp;lt;/detail&amp;gt;" max_match=150&lt;BR /&gt;| mvexpand msg&lt;BR /&gt;| rex field=msg "messageId=\"(?&amp;lt;Code&amp;gt;\S+)\"|ordinal=\"(?&amp;lt;SeqNo&amp;gt;\S+)\"|time=\"(?&amp;lt;DetTime&amp;gt;\S+)\"|&amp;lt;param&amp;gt;(?&amp;lt;Message&amp;gt;[\d\D]*?)&amp;lt;/param&amp;gt;" max_match=150&lt;BR /&gt;| eval DetTime=DetTime/1000&lt;BR /&gt;| convert timeformat="%m/%d/%Y %H:%M:%S.%3Q" ctime(DetTime) AS Time&lt;BR /&gt;| table SeqNo, Time, Code, Message&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;while am running for other sequence number there is no issue for this the issue is&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 09:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752043#M3961</guid>
      <dc:creator>Praz_123</dc:creator>
      <dc:date>2025-08-22T09:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: query help in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752053#M3962</link>
      <description>&lt;P&gt;Have you try to run this SPL with macros expanded?&amp;nbsp;&lt;BR /&gt;You can do it in SPL box with key combinations Ctrl+Shift+E (windows) or Cmd+Shift+E (macOS).&lt;/P&gt;&lt;P&gt;With that way you could modify / comment out content of those macros and debug what will happen and where is the real issue.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 12:31:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752053#M3962</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-08-22T12:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: query help in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752064#M3963</link>
      <description>&lt;P&gt;Some of your messages have multiple sequence numbers (ordinals) and some have no sequence number. Try looking at the actual events which are causing you the issue and determine whether the rex needs to be updated to extract the msg field correctly to alleviate this problem&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 15:42:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/query-help-in-splunk-cloud/m-p/752064#M3963</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-08-22T15:42:40Z</dc:date>
    </item>
  </channel>
</rss>

