Grouping logs?

Comments

3 comments

  • Official comment
    Avatar
    David Woller

    Hey Kevin,

    I think the transaction operator may be what you're looking for. This allows you to specify "states" within the logs from given strings of text, and I think that you coul use this to create a state transaction for the serverA status logs. You could specify "serverA up" as the up state and "serverA down" as the down state and then track the occurrences of those states. The link below includes some examples from the transaction operator:

    https://help.sumologic.com/Search/Search-Query-Language/Transaction-Analytics/Transaction-Operator-Examples

    Please let me know if you have any additional questions or if this doesn't provide the functionality that you're looking for. Thanks!

    Comment actions Permalink
  • Avatar
    Kevin Fletcher

    Hi David, thanks!!

    0
    Comment actions Permalink
  • Avatar
    Kevin Fletcher

    Ok it looks like the `with` statements need to include "*searchterm*" wildcards for example. That worked for me to get the matches.

    Now I need to figure out the differences in timestamps based on these matches - I am trying to print out the two marked << in my original post. 

    I had found this page which was more helpful: https://help.sumologic.com/Search/Search-Query-Language/Transaction-Analytics

    0
    Comment actions Permalink

Please sign in to leave a comment.