Splunk Search

Transaction using regex or event -1

markthompson
Builder

Hello,
I'm using a transaction command and what I want to do is find the next event that has the format "{DATE} INFO"
and then use the event previous to the found event.

Any ideas?

For example, endswith="{SEARCH}-1"

Tags (2)
1 Solution

markthompson
Builder

I have found a solution.

The solution I encountered is to create a new sourcetype and use the "SHOULD_LINEMERGE" boolean attribute with the property of BREAK_ONLY_BEFORE set with the regex of where the new statements should start.

Hope this helps

View solution in original post

0 Karma

markthompson
Builder

I have found a solution.

The solution I encountered is to create a new sourcetype and use the "SHOULD_LINEMERGE" boolean attribute with the property of BREAK_ONLY_BEFORE set with the regex of where the new statements should start.

Hope this helps

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...