0
为了不记录大量的上下文信息,我想要使用这样一个事实,即在splunk中,我可以跟踪每个上下文何时打开/关闭。例如,对于给定的日志:Splunk:取决于当前事件上下文的临时变量?
2017-08-02 12:12:10.2342+00 - <A> - Enabled feature `feature.A`
2017-08-02 12:12:11.1000+00 - Some log message
2017-08-02 12:12:12.1000+00 - Another log message
2017-08-02 12:12:13.1000+00 - <B> - Enabled feature `feature.B`
2017-08-02 12:12:14.1000+00 - Third log message
2017-08-02 12:12:15.1000+00 - </A> - Disabled feature `feature.A`
2017-08-02 12:12:16.1000+00 - Fourth log message
2017-08-02 12:12:17.1000+00 - </B> - Disabled feature `feature.B`
2017-08-02 12:12:18.1000+00 - Fifth log message
...我想有以下瓦尔的结果:
Message | Feature.A | Feature.B
--------------------|-----------|----------
Some log message | + | -
Another log message | + | -
Third log message | + | +
Fourth log message | - | +
Fifth log message | - | -
是否有可能在Splunk的呢?