I am using Splunk to pull logs from one of my systems and I do this by searching for a particular timestamp that will then return the event. However, sometimes the information I need is not found in that particular event, but instead in the following lines of logs. How can I tell splunk to return the event as well as the following 20-30 lines or so? Please help!
Thanks!
never mind, I figured this out using the transaction command, sorry!
this worked, where 100 is the amount of lines requested.
transaction startswith=(
never mind, I figured this out using the transaction command, sorry!
this worked, where 100 is the amount of lines requested.
transaction startswith=(