Splunk Search

Put results in one row table

lgroot
Explorer

Hello,

I have got a question about a Query. This is the query:

index=security-mijnssp "View rendered = /error.jspx" OR "Er is een fout opgetreden op de JSF"  | rex "BSN=(?P<BSN>[^<]+) View" | rex "INFO  n.s.m.w.l(?P<INFO>[^<]+)"|rex "ERROR n.s.m.w.l(?P<ERROR>[^<]+)"|  table BSN, INFO, ERROR, _time

And this is how the table look likes:

alt text

My question is how i can put the results in one row? So that BSN, INFO, ERROR and Time are on the same line sorted by Time?

Thanks for the answer!

Tags (2)
0 Karma

grijhwani
Motivator

Look at the documentation for transactions, and use BSN as your transaction identifier.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...