There are several ways to access the field extractor. Which option automatically identifies data type, source type, and sample event?
The transaction command groups events that share a common value in a specified field, such as JSESSIONID, and that occur within a specified time range. The search command filters the results to show only the events that match the given value of JSESSIONID.This search groups the events by JSESSIONID and then shows only the events that have the value SD462K101C2F267 for JSESSIONID2
1: Splunk Core Certified Power User Track, page 9.2: Splunk Documentation, transaction command.
Limited Time Offer
25%
Off
Malinda
10 hours agoOmer
5 days ago