Splunk Search

how to skip a fixed number of characters after a conditional keyword

splunksogetiht
Explorer

I have a log that looks like that :

create message w-OtYwP8QD2WcAkmUgZEgg from DB and add it in the map.
create message cbB8MZnaRYmt1elBWW2i3w from DB and add it in the map.
Message 'P2S2mMJSTVSMO0OjrHh4Kw' was set to pause.
adding new message F6252jqPRbq6iaBLyiC6cw in Map - appli source = ASLC
ABDC parameter event received : parameter name = 'ACID', value = '---'.

I would like to skip the 22 characters that follow the keyword “message”. But that keyword is not present on all lines.
How shall I do that ?
Thank you
,

Tags (2)
0 Karma

OL
Communicator

Have you check the Splunk documentation: http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Anonymizedatausingconfigurationfiles . Did this help? If not, let us know why.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...