Splunk Search

Transaction using regex or event -1

markthompson
Builder

Hello,
I'm using a transaction command and what I want to do is find the next event that has the format "{DATE} INFO"
and then use the event previous to the found event.

Any ideas?

For example, endswith="{SEARCH}-1"

Tags (2)
1 Solution

markthompson
Builder

I have found a solution.

The solution I encountered is to create a new sourcetype and use the "SHOULD_LINEMERGE" boolean attribute with the property of BREAK_ONLY_BEFORE set with the regex of where the new statements should start.

Hope this helps

View solution in original post

0 Karma

markthompson
Builder

I have found a solution.

The solution I encountered is to create a new sourcetype and use the "SHOULD_LINEMERGE" boolean attribute with the property of BREAK_ONLY_BEFORE set with the regex of where the new statements should start.

Hope this helps

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...