Splunk Search

Flatten transaction

msarro
Builder

Greetings everyone. This is hopefully a pretty simple question - is there a way to "flatten" transactions? After it runs, you end up with a transaction which is a multiline event. What I'd like to do is flatten the lines into a single line of text. For items where there are multiple matching lines, compress them into a single line which is semicolon delimited or something. Any ideas?

Tags (1)
0 Karma

Ayn
Legend

You could replace newline characters using rex:

<yoursearch> | rex field=_raw mode=sed "s/[\r\n]//g"

The default output in the search app will still wrap lines though, so if you want everything unwrapped on one single line one option would be to use table.

<yoursearch> | eval eventtext=_raw | table _time eventtext

(using _raw directly in table does not work).

0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...