<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fetch the details in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/673007#M230478</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263673"&gt;@svodela&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;let me know if I can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jan 2024 13:12:52 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-01-02T13:12:52Z</dc:date>
    <item>
      <title>Fetch the details</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/672992#M230474</link>
      <description>&lt;P&gt;We are trying to create a dashboard to understand the usage of our application version something like shown below&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Application Name&lt;/TD&gt;&lt;TD width="50%"&gt;Version&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;sgs&lt;/TD&gt;&lt;TD width="50%"&gt;1.0.18&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we search for particular index ""sgs1.0.18*" source="/data/wso2/api_manager/current/repository/logs/wso2carbon.log" we get below result.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;&amp;lt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;uri=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;get&lt;/SPAN&gt; &lt;SPAN class=""&gt;api/mydetails/1.0.0/apime/employee-details&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;SPAN class=""&gt;correlation-sit=sgs1.0.18u&lt;/SPAN&gt;&lt;SPAN&gt;%26&lt;/SPAN&gt;&lt;SPAN class=""&gt;h&lt;/SPAN&gt;&lt;SPAN&gt;%3d&lt;/SPAN&gt;&lt;SPAN class=""&gt;106&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;SERVICE_PREFIX=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;get&lt;/SPAN&gt; &lt;SPAN class=""&gt;api/mydetails/1.0.0/apime/employee-details&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;SPAN class=""&gt;correlation-sit=sgs1.0.18u&lt;/SPAN&gt;&lt;SPAN&gt;%26&lt;/SPAN&gt;&lt;SPAN class=""&gt;h&lt;/SPAN&gt;&lt;SPAN&gt;%3d&lt;/SPAN&gt;&lt;SPAN class=""&gt;106&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;path=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;get&lt;/SPAN&gt; &lt;SPAN class=""&gt;api/mydetails/1.0.0/apime/employee-details&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;SPAN class=""&gt;correlation-sit=sgs1.0.18u&lt;/SPAN&gt;&lt;SPAN&gt;%26&lt;/SPAN&gt;&lt;SPAN class=""&gt;h&lt;/SPAN&gt;&lt;SPAN&gt;%3d&lt;/SPAN&gt;&lt;SPAN class=""&gt;106&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;resourceMethod=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;get&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;HTTP_METHOD=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;get&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;resourceUri=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;api/mydetails/1.0.0/apime/employee-details&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;SPAN class=""&gt;correlation-sit=sgs1.0.18u&lt;/SPAN&gt;&lt;SPAN&gt;%26&lt;/SPAN&gt;&lt;SPAN class=""&gt;h&lt;/SPAN&gt;&lt;SPAN&gt;%3d&lt;/SPAN&gt;&lt;SPAN class=""&gt;106&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Could you please help us to give sample splunk query to achieve the results .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 10:58:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/672992#M230474</guid>
      <dc:creator>svodela</dc:creator>
      <dc:date>2024-01-02T10:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Fetch the details</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/672998#M230476</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263673"&gt;@svodela&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you're sure that you applications haven't numbers in their name and that version is always in the format "nn.nn.nn", you could use a regex like the following to extract apps and versions and run a search like the following:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| rex "correlation-sit=(?&amp;lt;app&amp;gt;[A-Za-z]+)(?&amp;lt;version&amp;gt;\d+\.\d+\.\d+)"
| table app version&lt;/LI-CODE&gt;&lt;P&gt;you can check the regex at&amp;nbsp;&lt;A href="https://regex101.com/r/FNieNJ/1" target="_blank"&gt;https://regex101.com/r/FNieNJ/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 12:05:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/672998#M230476</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-02T12:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Fetch the details</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/673005#M230477</link>
      <description>&lt;P&gt;Thank you Giuseppe. Appreciate your support. This query has helped us to do what we are looking for.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 13:08:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/673005#M230477</guid>
      <dc:creator>svodela</dc:creator>
      <dc:date>2024-01-02T13:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Fetch the details</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/673007#M230478</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263673"&gt;@svodela&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;let me know if I can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 13:12:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/673007#M230478</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-02T13:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: Fetch the details</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/673008#M230479</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry to come back , is there any way to change the table label.&lt;/P&gt;&lt;P&gt;example of my search:&lt;/P&gt;&lt;P&gt;"sgs1.0.*" source="/data/wso2/api_manager/current/repository/logs/wso2carbon.log" | rex "correlation-sit=(?&amp;lt;app&amp;gt;[A-Za-z]+)(?&amp;lt;version&amp;gt;\d+\.\d+\.\d+)" | table app version userId date_mday| dedup userId | sort version&lt;/P&gt;&lt;P&gt;can my table looks like below&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%"&gt;app&lt;/TD&gt;&lt;TD width="25%"&gt;version&lt;/TD&gt;&lt;TD width="25%"&gt;userid&lt;/TD&gt;&lt;TD width="25%"&gt;Date ( rather than&amp;nbsp;date_mday)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 02 Jan 2024 13:17:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/673008#M230479</guid>
      <dc:creator>svodela</dc:creator>
      <dc:date>2024-01-02T13:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: Fetch the details</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/673010#M230481</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;- I was able to fine the way with rename&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;"sgs1.0.*" source="/data/wso2/api_manager/current/repository/logs/wso2carbon.log" | rex "correlation-sit=(?&amp;lt;app&amp;gt;[A-Za-z]+)(?&amp;lt;version&amp;gt;\d+\.\d+\.\d+)" | table app version userId date_mday| dedup userId | sort version | fields "app", "date_mday", "userId", "version" | rename "date_mday" AS "Date"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 02 Jan 2024 15:26:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/673010#M230481</guid>
      <dc:creator>svodela</dc:creator>
      <dc:date>2024-01-02T15:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Fetch the details</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/673011#M230482</link>
      <description>&lt;P&gt;Add this line to the end of the query&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rename date_mday as Date&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 02 Jan 2024 13:36:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Fetch-the-details/m-p/673011#M230482</guid>
      <dc:creator>dtburrows3</dc:creator>
      <dc:date>2024-01-02T13:36:11Z</dc:date>
    </item>
  </channel>
</rss>

