Splunk Search

Howto display search result matching a keyword and few line before and after the keyword matched

krusovice
Path Finder

Hello,

I've this specific requirement for log search when matching a keyword, the result show display the matched event and 5 lines before and after the matched event.

The search is simple as below:

index="booking" host=* "CreateBookingError"| table _raw

The objective is to know the chronological of events matching this keyword. How can I achieve it?

Thanks.

0 Karma

jaime_ramirez
Communicator
0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...