Splunk Search

Put results in one row table

lgroot
Explorer

Hello,

I have got a question about a Query. This is the query:

index=security-mijnssp "View rendered = /error.jspx" OR "Er is een fout opgetreden op de JSF"  | rex "BSN=(?P<BSN>[^<]+) View" | rex "INFO  n.s.m.w.l(?P<INFO>[^<]+)"|rex "ERROR n.s.m.w.l(?P<ERROR>[^<]+)"|  table BSN, INFO, ERROR, _time

And this is how the table look likes:

alt text

My question is how i can put the results in one row? So that BSN, INFO, ERROR and Time are on the same line sorted by Time?

Thanks for the answer!

Tags (2)
0 Karma

grijhwani
Motivator

Look at the documentation for transactions, and use BSN as your transaction identifier.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...