<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get Start and End time from failed condition in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Start-and-End-time-from-failed-condition/m-p/537565#M151987</link>
    <description>&lt;P&gt;Alright, If I understand that correctly, you need first time and last time of the records after the last successful request (200). If that's the case in the latest sample data , StartError of the 4th 500 should be 2021-01-27T09:54:00.223Z and EndError should be 2021-01-27T09:57:45.564Z&lt;/P&gt;&lt;P&gt;If the above assumption is correct , try using below search with your existing search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval flag=if(status_code="200 OK",1,0)|accum flag as group
| eventstats first(eval(if(status_code!="200 OK",datetime,null()))) as StartError ,last(eval(if(status_code!="200 OK",datetime,null()))) as EndError,count(eval(status_code!="200 OK")) as sumcall by Name,group
| fields - flag,group
| eval StartError=if(status_code=="200 OK","-",StartError) 
| eval EndError=if(status_code=="200 OK","-",EndError) 
| eval sumcall=if(status_code=="200 OK","-",sumcall)&lt;/LI-CODE&gt;&lt;P&gt;Sample Result&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="renjith_nair_0-1611816061478.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12715iA49722E01740202A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="renjith_nair_0-1611816061478.png" alt="renjith_nair_0-1611816061478.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jan 2021 06:41:10 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2021-01-28T06:41:10Z</dc:date>
    <item>
      <title>How to get Start and End time from failed condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Start-and-End-time-from-failed-condition/m-p/537378#M151917</link>
      <description>&lt;P&gt;Hi Splunk,&lt;/P&gt;&lt;P&gt;We have data like this: ( how to get the result like on the table StartError EndError and SumCall ?) I have tried with command ' eventstats first(datetime) as StartError last(datetime) as EndError by status_code' but the result is not like we expected.&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;&lt;TABLE width="1333"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="221.6px" height="24px"&gt;datetime&lt;/TD&gt;&lt;TD width="361.6px" height="24px"&gt;Name&lt;/TD&gt;&lt;TD width="109.6px" height="24px"&gt;app_version&lt;/TD&gt;&lt;TD width="206.4px" height="24px"&gt;status_code&lt;/TD&gt;&lt;TD width="189.6px" height="24px"&gt;StartError&lt;/TD&gt;&lt;TD width="174.4px" height="24px"&gt;EndError&lt;/TD&gt;&lt;TD width="68.8px" height="24px"&gt;sumcall&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="221.6px" height="24px"&gt;2021-01-25T11:22:34.848Z&lt;/TD&gt;&lt;TD width="361.6px" height="24px"&gt;AAAA&lt;/TD&gt;&lt;TD width="109.6px" height="24px"&gt;1.0.0&lt;/TD&gt;&lt;TD width="206.4px" height="24px"&gt;403 Forbidden&lt;/TD&gt;&lt;TD width="189.6px" height="72px"&gt;2021-01-25T11:22:34.848Z&lt;/TD&gt;&lt;TD width="174.4px" height="72px"&gt;2021-01-25T12:01:45.478Z&lt;/TD&gt;&lt;TD width="68.8px" height="72px"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="221.6px" height="24px"&gt;2021-01-25T11:24:23.242Z&lt;/TD&gt;&lt;TD width="361.6px" height="24px"&gt;AAAA&lt;/TD&gt;&lt;TD width="109.6px" height="24px"&gt;1.0.0&lt;/TD&gt;&lt;TD width="206.4px" height="24px"&gt;403 Forbidden&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="221.6px" height="24px"&gt;2021-01-25T12:01:45.478Z&lt;/TD&gt;&lt;TD width="361.6px" height="24px"&gt;AAAA&lt;/TD&gt;&lt;TD width="109.6px" height="24px"&gt;1.0.0&lt;/TD&gt;&lt;TD width="206.4px" height="24px"&gt;403 Forbidden&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="221.6px" height="24px"&gt;2021-01-25T10:07:25.753Z&lt;/TD&gt;&lt;TD width="361.6px" height="24px"&gt;AAAA&lt;/TD&gt;&lt;TD width="109.6px" height="24px"&gt;1.0.0&lt;/TD&gt;&lt;TD width="206.4px" height="24px"&gt;200 OK&lt;/TD&gt;&lt;TD width="189.6px" height="24px"&gt;-&lt;/TD&gt;&lt;TD width="174.4px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="68.8px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="221.6px" height="45px"&gt;2021-01-26T07:55:51.835Z&lt;/TD&gt;&lt;TD width="361.6px" height="45px"&gt;BBBB&lt;/TD&gt;&lt;TD width="109.6px" height="45px"&gt;1.0.0&lt;/TD&gt;&lt;TD width="206.4px" height="45px"&gt;401 Unauthorized&lt;/TD&gt;&lt;TD width="189.6px" height="45px"&gt;2021-01-26T07:55:51.835Z&lt;/TD&gt;&lt;TD width="174.4px" height="45px"&gt;2021-01-26T07:55:51.835Z&lt;/TD&gt;&lt;TD width="68.8px" height="45px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="221.6px" height="24px"&gt;2021-01-26T08:00:14.970Z&lt;/TD&gt;&lt;TD width="361.6px" height="24px"&gt;BBBB&lt;/TD&gt;&lt;TD width="109.6px" height="24px"&gt;1.0.0&lt;/TD&gt;&lt;TD width="206.4px" height="24px"&gt;200 OK&lt;/TD&gt;&lt;TD width="189.6px" height="24px"&gt;-&lt;/TD&gt;&lt;TD width="174.4px" height="24px"&gt;-&lt;/TD&gt;&lt;TD width="68.8px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="221.6px" height="24px"&gt;2021-01-25T13:48:21.898Z&lt;/TD&gt;&lt;TD width="361.6px" height="24px"&gt;CCCC&lt;/TD&gt;&lt;TD width="109.6px" height="24px"&gt;1.0.0&lt;/TD&gt;&lt;TD width="206.4px" height="24px"&gt;403 Forbidden&lt;/TD&gt;&lt;TD width="189.6px" height="120px"&gt;2021-01-25T13:48:21.898Z&lt;/TD&gt;&lt;TD width="174.4px" height="120px"&gt;2021-01-25T13:48:40.131Z&lt;/TD&gt;&lt;TD width="68.8px" height="120px"&gt;&lt;P&gt;5&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="221.6px" height="24px"&gt;2021-01-25T13:48:23.851Z&lt;/TD&gt;&lt;TD width="361.6px" height="24px"&gt;CCCC&lt;/TD&gt;&lt;TD width="109.6px" height="24px"&gt;1.0.0&lt;/TD&gt;&lt;TD width="206.4px" height="24px"&gt;403 Forbidden&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="221.6px" height="24px"&gt;2021-01-25T13:48:25.338Z&lt;/TD&gt;&lt;TD width="361.6px" height="24px"&gt;CCCC&lt;/TD&gt;&lt;TD width="109.6px" height="24px"&gt;1.0.0&lt;/TD&gt;&lt;TD width="206.4px" height="24px"&gt;403 Forbidden&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="221.6px" height="24px"&gt;2021-01-25T13:48:38.672Z&lt;/TD&gt;&lt;TD width="361.6px" height="24px"&gt;CCCC&lt;/TD&gt;&lt;TD width="109.6px" height="24px"&gt;1.0.0&lt;/TD&gt;&lt;TD width="206.4px" height="24px"&gt;403 Forbidden&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="221.6px" height="24px"&gt;2021-01-25T13:48:40.131Z&lt;/TD&gt;&lt;TD width="361.6px" height="24px"&gt;CCCC&lt;/TD&gt;&lt;TD width="109.6px" height="24px"&gt;1.0.0&lt;/TD&gt;&lt;TD width="206.4px" height="24px"&gt;403 Forbidden&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 27 Jan 2021 09:14:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-Start-and-End-time-from-failed-condition/m-p/537378#M151917</guid>
      <dc:creator>bernanda</dc:creator>
      <dc:date>2021-01-27T09:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Start and End time from failed condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Start-and-End-time-from-failed-condition/m-p/537382#M151918</link>
      <description>&lt;P&gt;Try adding this to your search and test&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"Your search"
| eventstats first(eval(if(status_code!="200 OK",datetime,null()))) as StartError ,last(eval(if(status_code!="200 OK",datetime,null()))) as EndError,count(eval(status_code!="200 OK")) as sumcall by Name 
| eval StartError=if(status_code=="200 OK","-",StartError) 
| eval EndError=if(status_code=="200 OK","-",EndError) 
| eval sumcall=if(status_code=="200 OK","-",sumcall)&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 27 Jan 2021 10:14:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-Start-and-End-time-from-failed-condition/m-p/537382#M151918</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2021-01-27T10:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Start and End time from failed condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Start-and-End-time-from-failed-condition/m-p/537550#M151981</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/136781" target="_self"&gt;&lt;SPAN class="login-bold"&gt;renjith_nair&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your reply. The command it works, but the result "sumcall" count all status != "200 OK"&amp;nbsp; and collect the datetime from first and last not from the first error and last error before status_code="200 OK"&lt;BR /&gt;&lt;BR /&gt;I expected the "StartError" get datetime from the first of !="200 OK" and "EndError" get datetime from the last of ="200 OK" and "SumCall" only sum how many the Error before 200 OK and not all of !="200 OK"&lt;BR /&gt;&lt;BR /&gt;Like this table: (For the 200 OK, there is no StartError, EndError, and SumCall&lt;/P&gt;&lt;TABLE width="1103"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="223"&gt;datetime&lt;/TD&gt;&lt;TD width="134"&gt;Name&lt;/TD&gt;&lt;TD width="110"&gt;app_version&lt;/TD&gt;&lt;TD width="207"&gt;status_code&lt;/TD&gt;&lt;TD width="190"&gt;StartError&lt;/TD&gt;&lt;TD width="175"&gt;EndError&lt;/TD&gt;&lt;TD width="64"&gt;SumCall&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T08:51:53.559Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;200 OK&lt;/TD&gt;&lt;TD width="190"&gt;-&lt;/TD&gt;&lt;TD width="175"&gt;-&lt;/TD&gt;&lt;TD width="64"&gt;-&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T08:52:19.417Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;200 OK&lt;/TD&gt;&lt;TD width="190"&gt;-&lt;/TD&gt;&lt;TD width="175"&gt;-&lt;/TD&gt;&lt;TD width="64"&gt;-&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T08:53:32.198Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;200 OK&lt;/TD&gt;&lt;TD width="190"&gt;-&lt;/TD&gt;&lt;TD width="175"&gt;-&lt;/TD&gt;&lt;TD width="64"&gt;-&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T08:53:51.421Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;500 URL Open error&lt;/TD&gt;&lt;TD width="190"&gt;2021-01-27T08:53:51.421Z&lt;/TD&gt;&lt;TD width="175"&gt;2021-01-27T09:09:21.353Z&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:09:21.353Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;500 URL Open error&lt;/TD&gt;&lt;TD width="190"&gt;2021-01-27T08:53:51.421Z&lt;/TD&gt;&lt;TD width="175"&gt;2021-01-27T09:09:21.353Z&lt;/TD&gt;&lt;TD width="64"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:09:35.818Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;200 OK&lt;/TD&gt;&lt;TD width="190"&gt;-&lt;/TD&gt;&lt;TD width="175"&gt;-&lt;/TD&gt;&lt;TD width="64"&gt;-&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:10:10.618Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;200 OK&lt;/TD&gt;&lt;TD width="190"&gt;-&lt;/TD&gt;&lt;TD width="175"&gt;-&lt;/TD&gt;&lt;TD width="64"&gt;-&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:10:22.274Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;500 URL Open error&lt;/TD&gt;&lt;TD width="190"&gt;2021-01-27T09:10:22.274Z&lt;/TD&gt;&lt;TD width="175"&gt;2021-01-27T09:10:22.274Z&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:52:15.312Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;200 OK&lt;/TD&gt;&lt;TD width="190"&gt;-&lt;/TD&gt;&lt;TD width="175"&gt;-&lt;/TD&gt;&lt;TD width="64"&gt;-&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:52:26.469Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;200 OK&lt;/TD&gt;&lt;TD width="190"&gt;-&lt;/TD&gt;&lt;TD width="175"&gt;-&lt;/TD&gt;&lt;TD width="64"&gt;-&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:53:48.253Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;200 OK&lt;/TD&gt;&lt;TD width="190"&gt;-&lt;/TD&gt;&lt;TD width="175"&gt;-&lt;/TD&gt;&lt;TD width="64"&gt;-&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:54:00.223Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;500 URL Open error&lt;/TD&gt;&lt;TD width="190"&gt;2021-01-27T08:53:51.421Z&lt;/TD&gt;&lt;TD width="175"&gt;2021-01-27T08:53:51.421Z&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:57:41.246Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;500 URL Open error&lt;/TD&gt;&lt;TD width="190"&gt;2021-01-27T08:53:51.421Z&lt;/TD&gt;&lt;TD width="175"&gt;2021-01-27T09:57:45.564Z&lt;/TD&gt;&lt;TD width="64"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:57:45.564Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;500 URL Open error&lt;/TD&gt;&lt;TD width="190"&gt;2021-01-27T08:53:51.421Z&lt;/TD&gt;&lt;TD width="175"&gt;2021-01-27T09:57:45.564Z&lt;/TD&gt;&lt;TD width="64"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:58:19.772Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;200 OK&lt;/TD&gt;&lt;TD width="190"&gt;-&lt;/TD&gt;&lt;TD width="175"&gt;-&lt;/TD&gt;&lt;TD width="64"&gt;-&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="223"&gt;2021-01-27T09:58:36.630Z&lt;/TD&gt;&lt;TD width="134"&gt;AAAA&lt;/TD&gt;&lt;TD width="110"&gt;1.3.1&lt;/TD&gt;&lt;TD width="207"&gt;500 URL Open error&lt;/TD&gt;&lt;TD width="190"&gt;2021-01-27T09:58:36.630Z&lt;/TD&gt;&lt;TD width="175"&gt;2021-01-27T09:58:36.630Z&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 05:17:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-Start-and-End-time-from-failed-condition/m-p/537550#M151981</guid>
      <dc:creator>bernanda</dc:creator>
      <dc:date>2021-01-28T05:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Start and End time from failed condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Start-and-End-time-from-failed-condition/m-p/537565#M151987</link>
      <description>&lt;P&gt;Alright, If I understand that correctly, you need first time and last time of the records after the last successful request (200). If that's the case in the latest sample data , StartError of the 4th 500 should be 2021-01-27T09:54:00.223Z and EndError should be 2021-01-27T09:57:45.564Z&lt;/P&gt;&lt;P&gt;If the above assumption is correct , try using below search with your existing search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval flag=if(status_code="200 OK",1,0)|accum flag as group
| eventstats first(eval(if(status_code!="200 OK",datetime,null()))) as StartError ,last(eval(if(status_code!="200 OK",datetime,null()))) as EndError,count(eval(status_code!="200 OK")) as sumcall by Name,group
| fields - flag,group
| eval StartError=if(status_code=="200 OK","-",StartError) 
| eval EndError=if(status_code=="200 OK","-",EndError) 
| eval sumcall=if(status_code=="200 OK","-",sumcall)&lt;/LI-CODE&gt;&lt;P&gt;Sample Result&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="renjith_nair_0-1611816061478.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12715iA49722E01740202A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="renjith_nair_0-1611816061478.png" alt="renjith_nair_0-1611816061478.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 06:41:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-Start-and-End-time-from-failed-condition/m-p/537565#M151987</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2021-01-28T06:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Start and End time from failed condition</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-Start-and-End-time-from-failed-condition/m-p/537571#M151990</link>
      <description>&lt;P&gt;Wow, you save my time.&lt;/P&gt;&lt;P&gt;Thank you very very much, i am proud of your help.&lt;BR /&gt;Really nice&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 06:56:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-Start-and-End-time-from-failed-condition/m-p/537571#M151990</guid>
      <dc:creator>bernanda</dc:creator>
      <dc:date>2021-01-28T06:56:00Z</dc:date>
    </item>
  </channel>
</rss>

