You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从Splunk事件中提取唯一TransactionID及对应状态码

生成唯一TransactionID与对应状态码的Splunk查询

原始查询与返回事件

原始Splunk查询语句:

index=myIndex container_name="abc-mno-pqr" "status code :: 50*"

返回的事件日志:

[123-456-789-098] | 2023-07-26 12:05:31:245 [application-1] INFO com.example.event.SampleClasss - status code :: 500
[321-564-986-197] | 2023-07-26 13:04:38:287 [application-1] INFO com.example.event.SampleClasss - status code :: 503
[655-256-278-865] | 2023-07-26 13:05:42:245 [application-1] INFO com.example.event.SampleClasss - status code :: 503
[457-234-856-528] | 2023-07-26 14:08:23:123[application-1] INFO com.example.event.SampleClasss - status code :: 504
[457-234-856-528] | 2023-07-26 14:08:24:123[application-1] INFO com.example.event.SampleClasss - status code :: 504

问题说明

上述事件中,最后两条日志因时间戳仅相差1秒,导致TransactionID重复显示,需生成仅包含唯一TransactionID与对应状态码的结果表格。

解决方案查询

使用以下Splunk查询可提取字段并去重,生成目标表格:

index=myIndex container_name="abc-mno-pqr" "status code :: 50*"
| rex "\[(?<transactioId>[^\]]+)\]" 
| rex "status code :: (?<Status-Code>\d+)"
| dedup transactioId
| table transactioId Status-Code

最终结果表格

transactioIdStatus-Code
123-456-789-098500
321-564-986-197503
655-256-278-865503
457-234-856-528504

内容的提问来源于stack exchange,提问作者Sat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 19:41:25