clusterdetails

Use this command to look at log data within categories for specific classify results It enables you to expand a message signature into the individual log entries.

Syntax

clusterdetails collection=<collection_name> [<summary_expression>]

Parameters

The following table lists the parameters you can use with this command, along with their descriptions.

Parameter Description

collection_name

Use this parameter to specify the collection where the log data exists. The value for this variable should either be in the format β€˜<string>’ or β€œ<string>”.

summary_expression

Use this parameter to compare the ID to an expression. The value for this parameter should either be in the format id <cmp> or id <in_exp>.

cmp

Use this parameter as a comparison operator. The possible values for this variable include = and !=.

in_exp

This parameter should be in the format [NOT] IN β€œ(β€œ <value> (β€œ,”<value>)*”)”.

The following query returns the fatal logs included in ID 1, in the collection β€˜Fatal logs’.

Severity = fatal | clusterdetails collection = 'Fatal logs' id = 1

Was this article helpful?