Knowledge Management

How to "cut" information?

kozhin
New Member

Hello guys i have some log files that i need to be shown from place A to place B. with witch command i can do it? and if you can talk with me can you write me your skype if it possible. just want to ask more things. thx for understanding.

Tags (2)
0 Karma

chimell
Motivator

Hi kozhin
I Think that you can
- create two indexes A and B
- put your files in index A
-Then use This search code to tranfer its from A to B

    index=A |collect index=B
0 Karma

MichaelPriest
Communicator

Have you got an example of the data or some more detail on it?

You could have a look at the transaction command.

0 Karma

kozhin
New Member

Yes for sure. here is an example

resp_qid:   -1              issuer_posted:  0
smsgno:     0               sv_trace:   0
nwindicator:    0               timestamp:  0
devinfo:    []
hpan:       []
fld_flags:  00000000000000000000

17| =>proc_cmn_task_msg (cmn_task_msg.c)
strong text0| #---+++=== START MESSAGE LOG ===+++---#
Local date and time : 01/26/2015 12:02:32
0| 32.32.1C.31.35.30.1C.1C.42 22.150..B

0| Rcvd NEEDS_FORMAT message:
0| =>db_sel_ctla_tab (db_ctla.pc)
0| G_atm_uses_new_tables is set to [0]
0| atm_uses_new_tables: return FALSE
0| Rowid selected: [AAABfQAAJAAAAMsAAz]
0|

********************* CTLA_TAB structure ***********************
pid: 70150

ctype: 0 ttype: 700
tto: 1422262931 ntrans: 2961
respno: 101 msg_coord_num: 60
opstat: 0x80 procstat: 0x0008
oprob: 0x00
hreject: 0 areject:
.........
.........
.........

1| 00.00.00.00.00.00.00.00.00.80.97.01.00.80.A5.01
1| msgsnd_w_retry [dst task: TXROUT, time: 26/01/2015 12:02:32.0360]: trying to send 173d bytes to target queue 4194314
strong text1| msgsnd_w_retry [dst task: TXROUT, time: 26/01/2015 12:02:32.0360]: Send msg to queue 4194314
1| ACK sent into SV.
1| solproc: READY received (B).
1| opstat = 0x128, procstat = 0x0.
1| =>check_dynamic_keychg (atmi_stat.c)

I need from start message to msgnsd.. i tried to use breakonlybefore but i had some useless peaces of info. so i need your advice

0 Karma

laserval
Communicator

Is this when indexing data, or when searching on already indexed data? It sounds like you are having problems getting the events to break correctly. Do you want to skip parts of the log files when indexing?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...