Getting Data In

at index time, merge multiple lines with the same timestamp

psaminadin
New Member

Hi there

  • our customer have a custom app we cannot modify
  • for each unique event, the app send a log with 2 or 3 lines
  • each line have the same timestamp
  • and nothing else is common (no "event id")

The result of default indexation :
- for each line splunk sees a different event

The result the customer is expecting :
- one event that merge all the lines with same timestamp

we are looking for a way to merge lines based on timestamp at index time

Someone got a recipe ?

Best regards

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi psaminadin,
to merge events at indextime, you have to find a way to know when an event breaks.
Anyway, you can display events all together at search time using transaction (I don't like this solution) or stats command.

If you could share some example and the results you expect, it could be possible to help you.

Bye.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...