Splunk Search

Transaction using regex or event -1

markthompson
Builder

Hello,
I'm using a transaction command and what I want to do is find the next event that has the format "{DATE} INFO"
and then use the event previous to the found event.

Any ideas?

For example, endswith="{SEARCH}-1"

Tags (2)
1 Solution

markthompson
Builder

I have found a solution.

The solution I encountered is to create a new sourcetype and use the "SHOULD_LINEMERGE" boolean attribute with the property of BREAK_ONLY_BEFORE set with the regex of where the new statements should start.

Hope this helps

View solution in original post

0 Karma

markthompson
Builder

I have found a solution.

The solution I encountered is to create a new sourcetype and use the "SHOULD_LINEMERGE" boolean attribute with the property of BREAK_ONLY_BEFORE set with the regex of where the new statements should start.

Hope this helps

View solution in original post

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!