Knowledge Management

How to restrict btool stanzas without wildcards?

jason0
Path Finder

Hello, 

I am using splunk 9.0.0.1, and running btool to list out my index settings.  The trouble is I only want one stanza, but btool treats the stanza as a wildcard.

splunk btool --debug indexes list cisco

I get all stanza's with "cisco" in them (there are 51 of them, including "index=cisco").  how do restrict this?  I only want the "cisco" index.

--jason

0 Karma
1 Solution

goncalocoelho
Path Finder

Hi,

Have you tried btool command with grep? Something like this...

splunk btool --debug indexes list | grep -A 10 "[cisco]"

-A flag will show you N lines after the string your are looking for

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

jason0
Path Finder

I admit, I had hoped there was a way to do it within btool itself, but grep is always an option...

0 Karma

goncalocoelho
Path Finder

Hi,

Have you tried btool command with grep? Something like this...

splunk btool --debug indexes list | grep -A 10 "[cisco]"

-A flag will show you N lines after the string your are looking for

 

---
If this reply helps you, Karma would be appreciated.

0 Karma
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...