Splunk Search

how to skip a fixed number of characters after a conditional keyword

splunksogetiht
Explorer

I have a log that looks like that :

create message w-OtYwP8QD2WcAkmUgZEgg from DB and add it in the map.
create message cbB8MZnaRYmt1elBWW2i3w from DB and add it in the map.
Message 'P2S2mMJSTVSMO0OjrHh4Kw' was set to pause.
adding new message F6252jqPRbq6iaBLyiC6cw in Map - appli source = ASLC
ABDC parameter event received : parameter name = 'ACID', value = '---'.

I would like to skip the 22 characters that follow the keyword “message”. But that keyword is not present on all lines.
How shall I do that ?
Thank you
,

Tags (2)
0 Karma

OL
Communicator

Have you check the Splunk documentation: http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Anonymizedatausingconfigurationfiles . Did this help? If not, let us know why.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...