Splunk Search

How to get two fields in two lines in one event ?

alwagia87
New Member

I'm hoping to get help.

I have the below errors that are in the same event at in different lines.
i would like to get the 1st column as Error, 2nd as count and 3rd as App.

<Dsc>General Error:CODE0001-3032-CODE000-Error Msg 1</Dsc>
               <RpBy AppCd="EFG"/>
<Dsc>General Error:CODE0001-3032-CODE050-Error Msg 2</Dsc>
               <RpBy AppCd="XYZ"/>
<Dsc>General Error: Error, ANYTHING</Dsc>
               <RpBy AppCd="ABCD"/>

Error msg is always after "General Error:" I was able to get it but I want to add the App name in the 2nd line in the same event.

rex field=_raw max_match=100 ""General Error:(?<error>[\`\~\:\-\{\}\[\]\;\'\""\*\&\%\$\#\@\!\(\)\^\\=\-\?\/\.\,\\/\w+\d+\s+]+)<\/Dsc>""

The app name in the second line within the double quote.

The results should be:

Error                                                                       APP                  count
1. CODE0001-3032-CODE000-Error Msg 1           EFG                   1
2. CODE0001-3032-CODE050-Error Msg 2           XYZ                   1
3. Error, ANYTHING                                                  ABCD                1
0 Karma

to4kawa
Ultra Champion
| makeresults 
| eval _raw="<Dsc>General Error:CODE0001-3032-CODE000-Error Msg 1</Dsc>
 <RpBy AppCd=\"EFG\"/>
<Dsc>General Error:CODE0001-3032-CODE050-Error Msg 2</Dsc>
 <RpBy AppCd=\"XYZ\"/>
<Dsc>General Error: Error, ANYTHING</Dsc>
 <RpBy AppCd=\"ABCD\"/>"

| rename COMMENT as "this is sample you provide. from here, the logic"
| multikv noheader=t
| fields - Column* linecount 

| spath
| streamstats count(Dsc) as session
| selfjoin session
| eventstats count by Dsc
| rename RpBy{@AppCd} as APP
| rex field=Dsc mode=sed "s/General Error:\s*//"
| rename Dsc as Error
| table Error APP count

your log is XML, use spath

Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...