<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search log file based on timestamp from other file in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-log-file-based-on-timestamp-from-other-file/m-p/297172#M163870</link>
    <description>&lt;P&gt;How many entries will be there in the first sourcetype which contains the STARTTIME and ENDTIME? Do you want to display test run results all at once or one at a time?&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jan 2018 17:21:27 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2018-01-08T17:21:27Z</dc:date>
    <item>
      <title>Search log file based on timestamp from other file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-log-file-based-on-timestamp-from-other-file/m-p/297170#M163868</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;We have 2 files &lt;/P&gt;

&lt;P&gt;First File has only start time and end time of the test.&lt;/P&gt;

&lt;P&gt;STARTTIME                              ENDTIME&lt;BR /&gt;&lt;BR /&gt;
2018-01-04-17.49.29.497000      2018-01-04-18.35.44.945000&lt;/P&gt;

&lt;P&gt;Second File: Has the long entry from test run and past test runs&lt;/P&gt;

&lt;P&gt;We want to search second file based on start and end time of first file. Also second file that has long entry has time in format YYYY-MM-DDTHH:MM:SS,mSS.&lt;/P&gt;

&lt;P&gt;We are new to splunk and please suggest how we can fetch the desired results.&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Tushar&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 08:01:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-log-file-based-on-timestamp-from-other-file/m-p/297170#M163868</guid>
      <dc:creator>tushargupta1</dc:creator>
      <dc:date>2018-01-08T08:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: Search log file based on timestamp from other file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-log-file-based-on-timestamp-from-other-file/m-p/297171#M163869</link>
      <description>&lt;P&gt;Hi @tushargupta1,&lt;/P&gt;

&lt;P&gt;You can create a dashboard with 2 panels.&lt;/P&gt;

&lt;P&gt;1st panel will display table view with &lt;CODE&gt;Start Time&lt;/CODE&gt; and &lt;CODE&gt;End time&lt;/CODE&gt; columns. On Click of row that particular &lt;CODE&gt;Start Time&lt;/CODE&gt; and &lt;CODE&gt;End time&lt;/CODE&gt; will pass to the 2nd panels (by setting token).&lt;/P&gt;

&lt;P&gt;2nd panel will display all test case entries between the &lt;CODE&gt;Start Time&lt;/CODE&gt; and &lt;CODE&gt;End time&lt;/CODE&gt; .&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 13:14:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-log-file-based-on-timestamp-from-other-file/m-p/297171#M163869</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2018-01-08T13:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: Search log file based on timestamp from other file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-log-file-based-on-timestamp-from-other-file/m-p/297172#M163870</link>
      <description>&lt;P&gt;How many entries will be there in the first sourcetype which contains the STARTTIME and ENDTIME? Do you want to display test run results all at once or one at a time?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 17:21:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-log-file-based-on-timestamp-from-other-file/m-p/297172#M163870</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-01-08T17:21:27Z</dc:date>
    </item>
  </channel>
</rss>

