Deployment Architecture

How do I Search logs with two different logger ?

pratapfriends00
New Member

I have a scenario in which I have two logger one is for "writing to database" and the other is "successfully completed". Am trying for query which you give result when the first loggers is present but the second logger is missing to set alert when it fails to write to DB.

Tags (1)
0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Can you provide a sample of each event? Is there a common value that helps you tie the "writing to database" to the "successfully completed"? You could possibly use transaction command but will need more info from you regarding the events?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...