signature

Extracts a signature consisting of a set of special characters from the line field. This command is typically used to extract log samples by pattern type before developing a parser.

Syntax

signature

Usage

Extract the first sample log for each signature.

signature | stats first(line) by signature