Splunk Search

How can I return subsequent lines following an event?

dlespron
Path Finder

I am using Splunk to pull logs from one of my systems and I do this by searching for a particular timestamp that will then return the event. However, sometimes the information I need is not found in that particular event, but instead in the following lines of logs. How can I tell splunk to return the event as well as the following 20-30 lines or so? Please help!

Thanks!

Tags (1)
0 Karma
1 Solution

dlespron
Path Finder

never mind, I figured this out using the transaction command, sorry!

this worked, where 100 is the amount of lines requested.

transaction startswith=() maxevents=100

View solution in original post

0 Karma

dlespron
Path Finder

never mind, I figured this out using the transaction command, sorry!

this worked, where 100 is the amount of lines requested.

transaction startswith=() maxevents=100

0 Karma
Get Updates on the Splunk Community!

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...

Splunk Observability Cloud | Enhancing Your Onboarding Experience with the ...

We understand that your initial experience with getting data into Splunk Observability Cloud is crucial as it ...