Grouping and Correlating

Karun Subramanian · Apress eBooks · 2020

When you collect your log data from multiple data sources such as network devices, servers, and applications, the need for correlating and grouping those logs may raise. For example, your application server log might store the transaction ID in the application server’s log files. If your application utilizes an external service, which is not uncommon, the transaction ID might appear on its log files. If you want to know the complete end-to-end activities of a particular transaction ID, you need to correlate your application server’s logs with the external service’s log files. Splunk’s SPL provides a rich set of commands to group data from multiple sources.

Read the paper · More papers on PaperTik