Hi All,
I am almost a starter in Splunk but my org uses this tool as a log management utility.
I need help in getting a direction so as to how to filter data from logs in a distributed a sync logging product.
Problem statement:
There are multiple log files on multiple Linux boxes getting generated every second.
I have been doing this using oracle external tables and Linux shell but need to do it in a better way using Splunk and need help, opinion's are highly appreciated
As @scelikok said, your description is a bit vague and without a sample (anonymized if needed - we don't need your internal secrets ;-)) of your data and description of what data you want to get from that it's pretty much impossible to help you because we have no idea what we're talking about.
Hi @Anurag101,
It is not possible to help without knowing your data. Also, the solution depends on whether data is extracted or not. If you can show some sample anonymized events, we can help by sample query.