Splunk Search

Creating table based on Logs

christinaef07
Loves-to-Learn Everything

Hi everyone, I need help creating a table based on my logs. My logs are formatted as follows: 

[2020-11-10 20:27:10,260]INFO - Logging info for Splunk:
[2020-11-10 20:27:10,260]INFO - spark_rc=0
[2020-11-10 20:27:10,260]INFO - status=success
[2020-11-10 20:27:10,260]INFO - clientName=foo
[2020-11-10 20:27:10,260]INFO - ID=123456
[2020-11-10 20:27:10,260] INFO - dag_ID=dag.py

I want to be able to express all this information from all of our logs in a table. For ex:

 

| Dag_ID |  Client Name |  Status   |spark_rc|

|dag.py    |          foo             |  success.     | 0      |

 

And more rows reading these fields from our other logs as well. For example, I want to see all these fields for our runs in the last 24 hrs. Can someone please help me with how to do this?

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Am I correct in presuming each log line is a different event in Splunk?  If so, what links related events together?  I see nothing common except time and that's probably not reliable, especially if more than one run happens at the same time..

---
If this reply helps you, Karma would be appreciated.
0 Karma

christinaef07
Loves-to-Learn Everything

Hello and thank you for responding! I am new to Splunk and not sure. Should I be formatting my logs so that I have all this information printed within one line? 

0 Karma

christinaef07
Loves-to-Learn Everything

For example, I can format the logs to produce something like this : 

splunk_log_info= [spark_rc=1, client_name=foo, dag_id=dag.py]

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...