<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to generate Previous Event Time into Current Event by matching a particular field value. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538743#M152325</link>
    <description>&lt;LI-CODE lang="markup"&gt;| reverse
| streamstats current=f window=0 last(Disconnected_time) as PreviousEventTime by Disconnected_Session_Name&lt;/LI-CODE&gt;&lt;P&gt;...switch first(Disconnected_time) with last(Disconnected_time).&lt;/P&gt;</description>
    <pubDate>Fri, 05 Feb 2021 11:23:17 GMT</pubDate>
    <dc:creator>tread_splunk</dc:creator>
    <dc:date>2021-02-05T11:23:17Z</dc:date>
    <item>
      <title>How to generate Previous Event Time into Current Event by matching a particular field value.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538723#M152318</link>
      <description>&lt;P&gt;Current Output :&lt;/P&gt;&lt;TABLE width="412"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="203.517px" height="24px"&gt;Disconnected_time&lt;/TD&gt;&lt;TD width="228.183px" height="24px"&gt;Disconnected_Session_Name&lt;/TD&gt;&lt;TD width="52.55px" height="24px"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="203.517px" height="24px"&gt;&lt;SPAN&gt;2021-02-02T02:04:29.000&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="228.183px" height="24px"&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD width="52.55px" height="24px"&gt;12&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="203.517px" height="24px"&gt;2021-02-02T02:15:55.000&lt;/TD&gt;&lt;TD width="228.183px" height="24px"&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD width="52.55px" height="24px"&gt;6&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="203.517px" height="24px"&gt;2021-02-02T03:25:10.000&lt;/TD&gt;&lt;TD width="228.183px" height="24px"&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD width="52.55px" height="24px"&gt;11&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="203.517px" height="24px"&gt;2021-02-02T09:30:59.000&lt;/TD&gt;&lt;TD width="228.183px" height="24px"&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD width="52.55px" height="24px"&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PreviousEventTime should be generated based on "Disconnected_Session_Name" match&lt;/P&gt;&lt;P&gt;Example :&lt;/P&gt;&lt;TABLE width="573"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="161"&gt;Disconnected_time&lt;/TD&gt;&lt;TD width="187"&gt;Disconnected_Session_Name&lt;/TD&gt;&lt;TD width="64"&gt;count&lt;/TD&gt;&lt;TD width="161"&gt;PreviousEventTime&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;2021-02-02T02:04:29.000&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;12&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T02:15:55.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="161"&gt;2021-02-02T03:25:10.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;11&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;2021-02-02T02:04:29.000&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T09:30:59.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt;2021-02-02T02:15:55.000&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 09:43:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538723#M152318</guid>
      <dc:creator>vn_g</dc:creator>
      <dc:date>2021-02-05T09:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate Previous Event Time into Current Event by matching a particular field value.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538732#M152319</link>
      <description>&lt;P&gt;| streamstats current=f window=1 first(Disconnected_time) as PreviousEventTime by&amp;nbsp;&lt;SPAN&gt;Disconnected_Session_Name&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 10:21:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538732#M152319</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-02-05T10:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate Previous Event Time into Current Event by matching a particular field value.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538735#M152320</link>
      <description>&lt;P&gt;No, this is not generating the expected output. There are more than 200 session names which doesnot generate in any particular order.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 10:53:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538735#M152320</guid>
      <dc:creator>vn_g</dc:creator>
      <dc:date>2021-02-05T10:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate Previous Event Time into Current Event by matching a particular field value.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538736#M152321</link>
      <description>&lt;P&gt;Looking at it again, I think you need to reverse your results first...&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| reverse
| streamstats current=f window=1 first(Disconnected_time) as PreviousEventTime by Disconnected_Session_Name&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 10:56:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538736#M152321</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-02-05T10:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate Previous Event Time into Current Event by matching a particular field value.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538739#M152322</link>
      <description>&lt;P&gt;No, still it the same.&lt;/P&gt;&lt;P&gt;Current Output using streamstats :&lt;/P&gt;&lt;TABLE width="509"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="161"&gt;Disconnected_time&lt;/TD&gt;&lt;TD width="187"&gt;Disconnected_Session_Name&lt;/TD&gt;&lt;TD width="161"&gt;PreviousEventTime&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T23:31:37.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T23:25:15.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T17:58:18.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;2021-02-02T23:25:15.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T17:36:39.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;2021-02-02T17:58:18.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T16:32:07.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T16:28:41.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;2021-02-02T16:32:07.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T14:59:04.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T12:19:51.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Expected Output :&lt;/P&gt;&lt;TABLE width="509"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="161"&gt;Disconnected_time&lt;/TD&gt;&lt;TD width="187"&gt;Disconnected_Session_Name&lt;/TD&gt;&lt;TD width="161"&gt;PreviousEventTime&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T23:31:37.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T23:25:15.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T17:58:18.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;2021-02-02T23:25:15.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T17:36:39.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;2021-02-02T17:58:18.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T16:32:07.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;2021-02-02T23:31:37.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T16:28:41.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;2021-02-02T16:32:07.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T14:59:04.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;2021-02-02T17:36:39.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T12:19:51.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;2021-02-02T16:28:41.000&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 05 Feb 2021 11:07:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538739#M152322</guid>
      <dc:creator>vn_g</dc:creator>
      <dc:date>2021-02-05T11:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate Previous Event Time into Current Event by matching a particular field value.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538740#M152323</link>
      <description>&lt;P&gt;Replace window=1 with window=0.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 11:15:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538740#M152323</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-02-05T11:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate Previous Event Time into Current Event by matching a particular field value.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538742#M152324</link>
      <description>&lt;P&gt;No , the output is generating the same value for "PreviousEventTime" field.&lt;/P&gt;&lt;TABLE width="509"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="161"&gt;Disconnected_time&lt;/TD&gt;&lt;TD width="187"&gt;Disconnected_Session_Name&lt;/TD&gt;&lt;TD width="161"&gt;PreviousEventTime&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T23:31:37.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T23:25:15.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T17:58:18.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;2021-02-02T23:25:15.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T17:36:39.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;2021-02-02T23:25:15.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T16:32:07.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;2021-02-02T23:31:37.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T16:28:41.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;2021-02-02T23:31:37.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T14:59:04.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#27&lt;/TD&gt;&lt;TD&gt;2021-02-02T23:25:15.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2021-02-02T12:19:51.000&lt;/TD&gt;&lt;TD&gt;RDP-Tcp#10&lt;/TD&gt;&lt;TD&gt;2021-02-02T23:31:37.000&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 05 Feb 2021 11:19:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538742#M152324</guid>
      <dc:creator>vn_g</dc:creator>
      <dc:date>2021-02-05T11:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate Previous Event Time into Current Event by matching a particular field value.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538743#M152325</link>
      <description>&lt;LI-CODE lang="markup"&gt;| reverse
| streamstats current=f window=0 last(Disconnected_time) as PreviousEventTime by Disconnected_Session_Name&lt;/LI-CODE&gt;&lt;P&gt;...switch first(Disconnected_time) with last(Disconnected_time).&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 11:23:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538743#M152325</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-02-05T11:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate Previous Event Time into Current Event by matching a particular field value.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538746#M152327</link>
      <description>&lt;P&gt;One more go...&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| reverse
| streamstats current=f window=1 global=false last(Disconnected_time) as PreviousEventTime by Disconnected_Session_Name&lt;/LI-CODE&gt;&lt;P&gt;Have a look at the docs for streamstats and investigate the correct combination of window, global and first/last for your data set.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 11:29:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538746#M152327</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-02-05T11:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate Previous Event Time into Current Event by matching a particular field value.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538758#M152331</link>
      <description>&lt;P&gt;How are you getting on?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 12:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538758#M152331</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-02-05T12:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to generate Previous Event Time into Current Event by matching a particular field value.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538761#M152332</link>
      <description>&lt;P&gt;This helped. Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 13:02:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-generate-Previous-Event-Time-into-Current-Event-by/m-p/538761#M152332</guid>
      <dc:creator>vn_g</dc:creator>
      <dc:date>2021-02-05T13:02:00Z</dc:date>
    </item>
  </channel>
</rss>

