Monitoring Splunk

How do I skip ahead in a log file until I find a line with the text "Logging starting"?

cmorrall
Engager

I am investigating one of the log files in an application I want to monitor.

It seems there are over 100 lines at the start with information about the environment, startup parameters etc. I'm not really interested in that.

There is a line with the text "Logging starting..." or something similar.

What would the best way to tell Splunk to skip ahead until this particular line is found and start after that line? The lines following look like normal timestamped events with each event on a single line.

Tags (1)

harishalipaka
Motivator

hi @cmorrall

try like this

index="_internal" |head 2 |eval Apples=50,Bananas=44,results="Logout" |append [|makeresults |eval Apples=50,Bananas=44,results="Logout" ] |append [|makeresults |eval Apples=50,Bananas=44,results="Logout" ] |append [|makeresults |eval Apples=50,Bananas=44,results="Logging starting" ] |append [|makeresults |eval Apples=50,Bananas=44,results="Logout" ] |table Apples Bananas results |streamstats count as counting  |where counting > [search index="_internal" |head 2 |eval Apples=50,Bananas=44,results="Logout" |append [|makeresults |eval Apples=50,Bananas=44,results="Logout" ] |append [|makeresults |eval Apples=50,Bananas=44,results="Logout" ] |append [|makeresults |eval Apples=50,Bananas=44,results="Logging starting" ] |append [|makeresults |eval Apples=50,Bananas=44,results="Logout" ] |table Apples Bananas results |streamstats count as counting1 |where results="Logging starting"|return $counting1]
Thanks
Harish
0 Karma

DalJeanis
Legend

1) Are you saying that, when ingesting and indexing a file, you want to ignore all the records up to and including that text? If so, we will need the exact text and all "something similars" that you want to key on.
2) What kind of file is this? Is the entire file being added once, or is the same file being monitored as it is written to?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...