Activity Feed
- Posted How to use a part of a string in an event as a value and make it as an interesting field on Splunk Search. 02-04-2019 10:10 PM
- Tagged How to use a part of a string in an event as a value and make it as an interesting field on Splunk Search. 02-04-2019 10:10 PM
- Tagged How to use a part of a string in an event as a value and make it as an interesting field on Splunk Search. 02-04-2019 10:10 PM
- Tagged How to use a part of a string in an event as a value and make it as an interesting field on Splunk Search. 02-04-2019 10:10 PM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 |
02-04-2019
10:10 PM
"2018-10-30 05:11:35,659 AM|ERROR|(null)|(null)|(null)|System.Data.SqlClient.SqlException (0x80131904): Invalid column name 'GRP10227'.
at System.Data.SqlClient.SqlConnection.OnError(SqlException exception, Boolean breakConnection, Action`1 wrapCloseInAction........."
This particular event contains 33 lines. All exceptions follow the same pattern i.e. "|ERROR|(null)|(null)|(null)|(Type of Exception)"
I want to extract the text "System.Data.SqlClient.SqlException (0x80131904): Invalid column name 'GRP10227'." and make it as an interesting field.
When I used Delimiter method (Used Pipe to separate the texts) to extract the field, it displays all the 33 lines. But I want just the first line to be displayed as Value
For example,
I want a field called "Exception_type" and it should have values as the above text "|System.Data.SqlClient.SqlException (0x80131904): Invalid column name 'GRP10227'.".
Can you please help me on it
Thanks
... View more