我有一个 Splunk 日志,其中包含一条不同时间戳的消息,带有一些案例编号
"message":"Welcome home user case num 1ABCD-201901-765-2 UserId - 1203 XV - 543 UserAd - 76542 Elect - 5789875 Later Code - QWERZX"
在下面的日志中,如果满足某些条件,也会以不同的时间戳打印一些日志消息
"message":"Passed First class case num 1ABCD-201901-765-2"
"message":"Failed First class case num 1ABCD-201901-765-2"
"message":"Passed Second class case num 1ABCD-201901-765-2"
"message":"Fully Failed case num 1ABCD-201901-765-2"
"message":"Saved case num 1ABCD-201901-765-2"
"message":"Not saved case num 1ABCD-201901-765-2"
"message":"Not user to us case num 1ABCD-201901-765-2"
我想在 Splunk 仪表板中创建一个表,以使用带有这些列的 Splunk 查询列出所有案例编号以及详细信息
Case Num | XV | UserId | UserAd | Elect | Later Code | Passed First class | Passed Second class | Failed First class | Saved | Not saved | Not user to us
如何打印这些列 Passed First class | Passed Second class | Failed First class | Saved | Not saved | Not user to us
的真假