Reporting

How do I export first 5 minutes of a server log?

sebtardif
New Member

Everything I have is always sent to Splunk. We don't have any native files. I have a third party vendor that want the log of the first 5 minutes after my application server started. How can I do that?

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Write a search for the application logs spanning the period you need. Then click the Export icon and choose a format for the export.

---
If this reply helps you, Karma would be appreciated.
0 Karma

DalJeanis
Legend

So, to be even more specific -
1) Identify what source and index your server log is ingested into
2) identify the last time the server was started
3) run the search for that 5 minute timeframe.

Hopefully your logs will be complete, as long as you haven't set up the conf for that kind of data to send unwanted stuff to the nullqueue.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...