KB 052 – SM37 Filter
SM37 job filter can be used to send job logs and spool of the specified batch jobs to Splunk.
Once job name is specified (wildcards are supported), it is possible to define when job log or spool should be extracted depending on job status.
Please find sample of Splunk events below:
- Job log (EVENT_SUBTYPE=LOGS)
- Job spool (EVENT_SUBTYPE=SPOOL)
In both cases above SEQNUM field can be used as a line index to build the output in right order.