Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

at index time, merge multiple lines with the same timestamp

$
0
0
Hi there - our customer have a custom app we cannot modify - for each unique event, the app send a log with 2 or 3 lines - each line have the same timestamp - and nothing else is common (no "event id") The result of default indexation : - for each line splunk sees a different event The result the customer is expecting : - one event that merge all the lines with same timestamp we are looking for a way to merge lines based on timestamp **at index time** Someone got a recipe ? Best regards

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>