KB 052 – SM37 Filter

SM37 job filter can be used to send job logs and spool of the specified batch jobs to Splunk.

KB 052 - SM37 Filter

Once job name is specified (wildcards are supported), it is possible to define when job log or spool should be extracted depending on job status.

KB 052 - SM37 Filter

Please find sample of Splunk events below:

  1. Job log (EVENT_SUBTYPE=LOGS)
    KB 052 - SM37 Filter
  2. Job spool (EVENT_SUBTYPE=SPOOL)
    KB 052 - SM37 Filter

In both cases above SEQNUM field can be used as a line index to build the output in right order.

Download PDF version here