Splunk Search

Transaction using regex or event -1

markthompson
Builder

Hello,
I'm using a transaction command and what I want to do is find the next event that has the format "{DATE} INFO"
and then use the event previous to the found event.

Any ideas?

For example, endswith="{SEARCH}-1"

Tags (2)
1 Solution

markthompson
Builder

I have found a solution.

The solution I encountered is to create a new sourcetype and use the "SHOULD_LINEMERGE" boolean attribute with the property of BREAK_ONLY_BEFORE set with the regex of where the new statements should start.

Hope this helps

View solution in original post

0 Karma

markthompson
Builder

I have found a solution.

The solution I encountered is to create a new sourcetype and use the "SHOULD_LINEMERGE" boolean attribute with the property of BREAK_ONLY_BEFORE set with the regex of where the new statements should start.

Hope this helps

0 Karma
Get Updates on the Splunk Community!

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...

Splunk SOAR Now Available on Google Cloud Platform

We’re excited to announce that Splunk SOAR is now natively available as a SaaS solution on Google Cloud ...