Getting Data In

Unified log - how to?

shayhibah
Path Finder

Hi,

I would like to know if there is option to unify logs based on id or something else.

For example:
I have the initial log and after 15 sec, I get an update for that log (not necessarily sequential).

Is there any option to merge them into 1 log (instead of 2) and doing it before indexing (since I want to index 1 log)?

Thanks,
Shay

0 Karma

p_gurav
Champion

Hi,

You can do that with transaction command. Also refer documents for it:
https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Transaction

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...