SPL
Linux Cron Job Information
Description
This splunk query example uses regex (regular expressions) to extract information on Linux cron jobs.
*Note* this query has not been extensively tested
5 0
sourcetype="cron" | eval Date=strftime(_time, "%Y/%m/%d") | rex ".*:\d{2}\s(?<hostname>\S+)" | rex "]:\sfinished(?<Info>.*)" | stats count by Date, hostname, Info
Comments
0 total
Be the first to comment on this SPL.
Leave a comment
You must log in to post a comment.