<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: complicated subsearches in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/complicated-subsearches/m-p/60970#M15014</link>
    <description>&lt;P&gt;I'm not 100% sure that I fully understand what you are trying to do here, one possibility is to use &lt;CODE&gt;transaction&lt;/CODE&gt; search command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="server09282010" | transaction startswith=(INFO messageSize) mvlist=requestid | search 364a05b7-2beb-4c68-8459-52e6fc4612b3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;you may be able to open the search timeframe slightly, then use &lt;CODE&gt;stats&lt;/CODE&gt; to pull the values from across events, off the top of my head, I don't know if a specific "latest" value is inclusive of that exact timestamp, if it is then the &lt;CODE&gt;-1&lt;/CODE&gt; isn't needed...  (This may need some tweaking...) &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="server09282010" [search sourcetype="server09282010" 364a05b7-2beb-4c68-8459-52e6fc4612b3 | head 1 | eval latest(_time-1) | fields latest] | search MessageSizeBytes=* | head 1 | stats min(_time), values(requestid), list(MessageSizeBytes)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 30 Sep 2010 08:20:35 GMT</pubDate>
    <dc:creator>Lowell</dc:creator>
    <dc:date>2010-09-30T08:20:35Z</dc:date>
    <item>
      <title>complicated subsearches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/complicated-subsearches/m-p/60969#M15013</link>
      <description>&lt;P&gt;I have jboss logs that print a message size everytime jboss restarts. The message size is different everytime jboss starts and a message is displayed:&lt;/P&gt;

&lt;P&gt;2010-09-28 02:52:04,992 INFO messageSize=4194304bytes&lt;/P&gt;

&lt;P&gt;I have a field extraction for the messageSize.&lt;/P&gt;

&lt;P&gt;What I want to do now is pull this kind of log and determine what the message size is based upon the last time jboss started since the log (in case this before 04:43)&lt;/P&gt;

&lt;P&gt;2010-09-29 04:43:22,836 INFO  Request information [requestid=364a05b7-2beb-4c68-8459-52e6fc4612b3]&lt;/P&gt;

&lt;P&gt;I am able to pull one request and it's message size using the following splunk query: (Although I can't get the request id printed in the table)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="server09282010" [search sourcetype="server09282010" 364a05b7-2beb-4c68-8459-52e6fc4612b3 | head 1 | rename _time as latest| fields latest] |   WHERE MessageSizeBytes NOT NULL | head 1 | table _time MessageSizeBytes
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What i really want is a table with requestid and Message size (based upon the time when jboss was started)&lt;/P&gt;

&lt;P&gt;I hope this makes sense.. it is a complicated query.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 08:03:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/complicated-subsearches/m-p/60969#M15013</guid>
      <dc:creator>htkhtk</dc:creator>
      <dc:date>2010-09-30T08:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: complicated subsearches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/complicated-subsearches/m-p/60970#M15014</link>
      <description>&lt;P&gt;I'm not 100% sure that I fully understand what you are trying to do here, one possibility is to use &lt;CODE&gt;transaction&lt;/CODE&gt; search command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="server09282010" | transaction startswith=(INFO messageSize) mvlist=requestid | search 364a05b7-2beb-4c68-8459-52e6fc4612b3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;you may be able to open the search timeframe slightly, then use &lt;CODE&gt;stats&lt;/CODE&gt; to pull the values from across events, off the top of my head, I don't know if a specific "latest" value is inclusive of that exact timestamp, if it is then the &lt;CODE&gt;-1&lt;/CODE&gt; isn't needed...  (This may need some tweaking...) &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="server09282010" [search sourcetype="server09282010" 364a05b7-2beb-4c68-8459-52e6fc4612b3 | head 1 | eval latest(_time-1) | fields latest] | search MessageSizeBytes=* | head 1 | stats min(_time), values(requestid), list(MessageSizeBytes)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 30 Sep 2010 08:20:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/complicated-subsearches/m-p/60970#M15014</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-09-30T08:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: complicated subsearches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/complicated-subsearches/m-p/60971#M15015</link>
      <description>&lt;P&gt;The where does work as expected.. My main problem is getting a listing of all request ids with the message size (I am able to get one using the query above) I am trying the transaction approach to group everytime jboss was started but I don't think it is going to work for me&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 09:03:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/complicated-subsearches/m-p/60971#M15015</guid>
      <dc:creator>htkhtk</dc:creator>
      <dc:date>2010-09-30T09:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: complicated subsearches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/complicated-subsearches/m-p/60972#M15016</link>
      <description>&lt;P&gt;I got a transaction working to split out into 5 transaction statements for the 5 times jboss restarted and I can see the requestids in chunks.. is there a way to break those out?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 09:32:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/complicated-subsearches/m-p/60972#M15016</guid>
      <dc:creator>htkhtk</dc:creator>
      <dc:date>2010-09-30T09:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: complicated subsearches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/complicated-subsearches/m-p/60973#M15017</link>
      <description>&lt;P&gt;You're right about the where clause, that's a new one on me.  I did look in the docs and I didn't see that syntax, but its possible I missed it.  In any case, I updated my answer and removed that comment.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2010 20:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/complicated-subsearches/m-p/60973#M15017</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-09-30T20:14:25Z</dc:date>
    </item>
  </channel>
</rss>

