Splunk Search

How do I fetch a word along with the next five lines in a log and wrap it as an event?

zacksoft
Contributor

My logs are all parsed by time stamps into a new event. Every line in the log starts with a time stamp.

I am searching for the word "tron" and Splunk gives me that line that contains "tron".

But my requirement is:

Whenever I get the line containing "tron" as a search result , I want some SPL magic to fetch that line along with next 5 lines in the log and wrap it as an event in Splunk. I want to achieve this with Splunk Query .

I hope I am clear...

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Try this:

index=foo | transaction startswith="tron" maxevents=6 | ...
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try this:

index=foo | transaction startswith="tron" maxevents=6 | ...
---
If this reply helps you, Karma would be appreciated.
0 Karma

zacksoft
Contributor

@richgalloway ♦
Thank you. This helps.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...