Some of the long entries my app makes are composed of multiple lines.
I would like to keep it this way (a log line can be 10+ lines sometimes, has lots of info that can't be condensed into a single line).
Is there a way, given a specific text match, to view text lines near it?
E.g. supposed that my log format looks like this:
2013-01-07 13:28:27,325 INFO (LoggerName) Something is wrong with Website http://foo.com/
Now follow a few important details.
A few more details.
2013-01-07 13:28:27,325 INFO (LoggerName) Another log entry
If I search in splunk for "foo.com", and only find the first line without the details - how can I view the rest of the details?
I prefer a solution that won't force me to change the format of my log messages.
... View more