Hi all,
I am completely new to Splunk so I apologize if this has been asked/answered. I did review the past discussions but could not find a solution to my question.
I have incoming logs that look similar to this
Perhaps this will get you started.
index=foo "Initiating EnterpriseOne startup"
| rex "targets\\\(?<machine>[^\\\]+)"
| table _time machine
Thanks @richgalloway That worked great. I ended up with
index=* "Initiating EnterpriseOne startup"
| rex "targets\\\(?<machine>[^\\\]+)" | table machine _time
| dedup machine
| sort machine
As newbie, I appreciate your input.
I'm sure there is documentation out there somewhere. Now if I can just find it. ;^o
Bruce
For documentation, see https://docs.splunk.com/Documentation/Splunk/8.1.2/Search/GetstartedwithSearch and https://docs.splunk.com/Documentation/Splunk/8.1.2/SearchReference/WhatsInThisManual