Splunk Search

How can I extract specified fields from the log files uploaded in Splunk thru a UI?

tankhanandita
Explorer

I have created a UI which loads the user selected log file in Splunk. Now I have to extract some fields from that file and display that in a table format. How can I do it?
For the UI, I am using jsp and servlets.

0 Karma
1 Solution

woodcock
Esteemed Legend

Just run a search with something like this:

index=YourIndexHere | table YourFieldOne YourFieldTwo

View solution in original post

0 Karma

woodcock
Esteemed Legend

Just run a search with something like this:

index=YourIndexHere | table YourFieldOne YourFieldTwo
0 Karma

tankhanandita
Explorer

Thank you so much for your help. I did the same thing. It was a careless mistake i was trying to wrong fields from the log files.
Again thank u very much.

0 Karma

tankhanandita
Explorer

I have another question.Kindly help on this one also
I have extracted certain feilds using java sdk from splunk with the table command. How can i view that data as a table in my java form.
or
The data extracted is in the form of job. How can i convert that data into string, so that i can apply conditional operators on that data.

Thanks in advance for your help.

0 Karma

woodcock
Esteemed Legend

You are better off clicking Accept on this question and asking a new one. At this point, you and I are probably the only ones listening and you need a broader audience.

0 Karma

tankhanandita
Explorer

But what if my index contains multiple files that have some common fields and i only want to retrieve the data from one file and not all the files?

0 Karma

woodcock
Esteemed Legend

This is basic stuff.

index=YourIndexHere source=MyOneSourceFileHere | table YourFieldOne YourFieldTwo
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...