Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

how to get the first(_raw) when i have split my pattern which were separated by pipe "|" using eval and split command.

$
0
0
**unique_exception= pattern1|pattern2|pattern3** all these three patterns(1,2,3) are tagged to unique number 111. **eval temp=split(unique_exception, "|")|stats values(temp) by temp** i am getting output as follows **111 - pattern1** **111 - pattern2** **111 - pattern3** now how to get the first event for these individual events (pattern1 and pattern2 and pattern3) separately.

Viewing all articles
Browse latest Browse all 47296

Trending Articles