Splunk Search

Need help in extraction of data from distributed and async logging application

Anurag101
New Member

Hi All,

I am almost a starter in Splunk but my org uses this tool as a log management utility.

I need help in getting a direction so as to how to filter data from logs in a distributed a sync logging product.

Problem statement:

There are multiple log files on multiple Linux boxes getting generated every second.

  1. I need to search for ids created and relevant creation timestamps and the batches under which these ids exists.
  2. Filter the ids based on passed batches (this is another line in the same log file)
  3. Calculate the E2E timestamp for the id processing by searching the processed id in step-1 and substracting the timestamp of step 3 and step 1(this is again printed in the log files).

I have been doing this using oracle external tables and Linux shell but need to do it in a better way using Splunk and need help,  opinion's are highly appreciated 

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

As @scelikok said, your description is a bit vague and without a sample (anonymized if needed - we don't need your internal secrets ;-)) of your data and description of what data you want to get from that it's pretty much impossible to help you because we have no idea what we're talking about.

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @Anurag101,

It is not possible to help without knowing your data. Also, the solution depends on whether data is extracted or not.  If you can show some sample anonymized events, we can help by sample query.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...