Hi, pardon if my question is too obvious, am a Splunk noob.
My requirement is:
I have a search String , example "Error occured in getting ID....". In the result log of this search is included a unique ID (there are multiple logs for each time that searh string is matched, unique ID different for all such logs).
I want to further search for one specific log that has same unique ID plus some other text.
E.g - This is search string query:
index=index "Error finding xID for ID:" | dedup uniquId
This is one block of the result:
{"level":"ERROR","uniqueId":"48b3825e993981df25d13670 1", "message":"Error finding xID for ID:1234"}
What I require is, to be able to further search based on uniqueId in log dynamcially.
E.g:
| <uniqueId> "some other search string"
... View more