Alerting

How to create query to track multiple ORA numbers, we received different format logs as below?

jackin
Path Finder

I want to track multiple ORA numbers, we received different format logs as below, can you help me to write a query for this.

 

Logs/Events:

 

2022-08-04T06 : 55 : 54.009110 + 01 : 00 opiodr aborting process unknown ospid ( 8696 ) as a result of ORA - 609

2022-08-04T06 : 51 : 54.137474 + 01 : 00 WARNING : inbound connection timed out ( ORA - 3136 )

Labels (2)
0 Karma

tej57
Builder

Hello @jackin ,

You can write the below query to your base search to extract the ORA field.

| <your_base_query>
| rex field=_raw "(ORA - )(?P<ORA>\d+)"

 

---

If you find this answer helpful, an upvote is appreciated..!!

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...