Splunk Search

Can I generate a table in which I list every event with the four variables?

leon12
Loves-to-Learn

Hey Guys, I have the following data in Splunk. Each eventdata has 4 lines (which are seperated through newLines) and every line in a event represent the value of a variable. 

My Question: Can I generate a table in which I list every event with the four variables. The table I wont to have should look like the following excel table :

excelfile.PNG

 

Darstellung.PNG

Thanks for your help!

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @leon12,

I suppose that the Datum is also the timestamp of the event.

In this case, please try something like this:

<your_search>
|  rex "(?ms).*Description:\s(?<Description>.*).*Node:\s+(?<Node>.*).*Severity:\s+(?<Severity>.*)"
| table _time Description Node Severity

That you can test at https://regex101.com/r/tCns4x/1

If Datum isn't also the timestamp, you have two ways:

  • modify your props.conf to use Datum as timestamp (_time),
  • insert datum in the regex

I hint the first solution.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...