<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: find time gaps in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/find-time-gaps/m-p/574146#M200097</link>
    <description>&lt;P&gt;Thank you for answer,&lt;/P&gt;&lt;P&gt;actually the main issue is find patterns like this:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-10-25 08:59:50,725 INFO CUS.AbCD-VW2-1234567890 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-10-25 08:59:50,726 INFO CUS.AbCD-VW2-1234567890 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-10-25 08:59:52,730 INFO CUS.AbCD-VW2-0987654321 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-10-25 08:59:52,735 INFO CUS.AbCD-VW2-0987654321 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 08:59:54,736 INFO CUS.AbCD-VW2-6478523699 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 08:59:54,736 INFO CUS.AbCD-VW2-6632587411 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 08:59:54,737 INFO CUS.AbCD-VW2-6333322222 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:54,725 INFO CUS.AbCD-VW2-1478523699 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:58,705 INFO CUS.AbCD-VW2-9632587411 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:59,800 INFO CUS.AbCD-VW2-3333322222 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:59,805 INFO CUS.AbCD-VW2-9632587411 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:59,950 INFO CUS.AbCD-VW2-3333322222 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:59,955 INFO CUS.AbCD-VW2-1478523699 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 09:00:00,956 INFO CUS.AbCD-VW2-6632587411 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 09:00:00,956 INFO CUS.AbCD-VW2-6333322222 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 09:00:00,956 INFO CUS.AbCD-VW2-6478523699 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;sometimes lots of&amp;nbsp;&lt;FONT color="#FF0000"&gt;Packet Processed &lt;FONT color="#000000"&gt;come and related&amp;nbsp;&lt;FONT color="#993366"&gt;Send Packet &lt;FONT color="#000000"&gt;stuck in queue, need to find them.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;here is the flow:&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;1-(Packet Processed) node1&lt;STRONG&gt;send&amp;nbsp;packet to node2&lt;/STRONG&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;2-node2&amp;nbsp;(return response to node1) &amp;gt; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;3-(Send Packet) node1 &lt;STRONG&gt;send&amp;nbsp;packet to another node 3&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;as you see couple of times continuously (Packet Processed).&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Its duration varies, actually this is a pattern or behavior.&lt;/P&gt;&lt;P&gt;is there any way to do this with splunk?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Tue, 09 Nov 2021 07:46:03 GMT</pubDate>
    <dc:creator>indeed_2000</dc:creator>
    <dc:date>2021-11-09T07:46:03Z</dc:date>
    <item>
      <title>find time gaps</title>
      <link>https://community.splunk.com/t5/Splunk-Search/find-time-gaps/m-p/573938#M200012</link>
      <description>&lt;P&gt;Hi i have log like this, need to find where unusuall time gap between "Packet Processed" and "Send Packet" that exist&lt;/P&gt;&lt;P&gt;this is normal 001&lt;BR /&gt;2021-10-25 08:59:50,725 INFO CUS.AbCD-VW2-1234567890 [FlowProcessorService] Packet Processed:&lt;BR /&gt;2021-10-25 08:59:50,726 INFO CUS.AbCD-VW2-1234567890 [AppClientManager] Send Packet&lt;/P&gt;&lt;P&gt;this is normal 035&lt;BR /&gt;2021-10-25 08:59:52,730 INFO CUS.AbCD-VW2-0987654321 [FlowProcessorService] Packet Processed:&lt;BR /&gt;2021-10-25 08:59:52,735 INFO CUS.AbCD-VW2-0987654321 [AppClientManager] Send Packet&lt;/P&gt;&lt;P&gt;this is NOT normal 5:230&lt;BR /&gt;2021-10-25 08:59:54,725 INFO CUS.AbCD-VW2-1478523699 [FlowProcessorService] Packet Processed:&lt;BR /&gt;2021-10-25 08:59:59,955 INFO CUS.AbCD-VW2-1478523699 [AppClientManager] Send Packet&lt;/P&gt;&lt;P&gt;this is NOT normal 1:100&lt;BR /&gt;2021-10-25 08:59:58,705 INFO CUS.AbCD-VW2-9632587411 [FlowProcessorService] Packet Processed:&lt;BR /&gt;2021-10-25 08:59:59,805 INFO CUS.AbCD-VW2-9632587411 [AppClientManager] Send Packet&lt;/P&gt;&lt;P&gt;this is NOT normal 100&lt;BR /&gt;2021-10-25 08:59:59,800 INFO CUS.AbCD-VW2-3333322222 [FlowProcessorService] Packet Processed:&lt;BR /&gt;2021-10-25 08:59:59,950 INFO CUS.AbCD-VW2-3333322222 [AppClientManager] Send Packet&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;this is huge log and imagine lot's of line like this write to log file without order as i sort above need to know when count of unusuall time gaps increase.&lt;/P&gt;&lt;P&gt;2021-10-25 08:59:50,725 INFO CUS.AbCD-VW2-1234567890 [FlowProcessorService] Packet Processed:&lt;BR /&gt;2021-10-25 08:59:50,726 INFO CUS.AbCD-VW2-1234567890 [AppClientManager] Send Packet&lt;BR /&gt;2021-10-25 08:59:52,730 INFO CUS.AbCD-VW2-0987654321 [FlowProcessorService] Packet Processed:&lt;BR /&gt;2021-10-25 08:59:52,735 INFO CUS.AbCD-VW2-0987654321 [AppClientManager] Send Packet&lt;BR /&gt;2021-10-25 08:59:54,725 INFO CUS.AbCD-VW2-1478523699 [FlowProcessorService] Packet Processed:&lt;BR /&gt;2021-10-25 08:59:58,705 INFO CUS.AbCD-VW2-9632587411 [FlowProcessorService] Packet Processed:&lt;BR /&gt;2021-10-25 08:59:59,800 INFO CUS.AbCD-VW2-3333322222 [FlowProcessorService] Packet Processed:&lt;BR /&gt;2021-10-25 08:59:59,805 INFO CUS.AbCD-VW2-9632587411 [AppClientManager] Send Packet&lt;BR /&gt;2021-10-25 08:59:59,950 INFO CUS.AbCD-VW2-3333322222 [AppClientManager] Send Packet&lt;BR /&gt;2021-10-25 08:59:59,955 INFO CUS.AbCD-VW2-1478523699 [AppClientManager] Send Packet&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FYI: unusuall time gaps means increase time between "Packet Processed" &amp;amp; "Send Packet"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Sun, 07 Nov 2021 16:50:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/find-time-gaps/m-p/573938#M200012</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2021-11-07T16:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: find time gaps</title>
      <link>https://community.splunk.com/t5/Splunk-Search/find-time-gaps/m-p/573940#M200014</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="2021-10-25 08:59:50,725 INFO CUS.AbCD-VW2-1234567890 [FlowProcessorService] Packet Processed:
2021-10-25 08:59:50,726 INFO CUS.AbCD-VW2-1234567890 [AppClientManager] Send Packet
2021-10-25 08:59:52,730 INFO CUS.AbCD-VW2-0987654321 [FlowProcessorService] Packet Processed:
2021-10-25 08:59:52,735 INFO CUS.AbCD-VW2-0987654321 [AppClientManager] Send Packet
2021-10-25 08:59:54,725 INFO CUS.AbCD-VW2-1478523699 [FlowProcessorService] Packet Processed:
2021-10-25 08:59:58,705 INFO CUS.AbCD-VW2-9632587411 [FlowProcessorService] Packet Processed:
2021-10-25 08:59:59,800 INFO CUS.AbCD-VW2-3333322222 [FlowProcessorService] Packet Processed:
2021-10-25 08:59:59,805 INFO CUS.AbCD-VW2-9632587411 [AppClientManager] Send Packet
2021-10-25 08:59:59,950 INFO CUS.AbCD-VW2-3333322222 [AppClientManager] Send Packet
2021-10-25 08:59:59,955 INFO CUS.AbCD-VW2-1478523699 [AppClientManager] Send Packet"
| multikv noheader=t



| rex "(?&amp;lt;time&amp;gt;\d{4}-\d{2}-\d{2}\s\d{2}:\d{2}:\d{2},\d{3})\sINFO\s(?&amp;lt;txid&amp;gt;[\S]+)\s\[[^\]]+\]\s.*(?&amp;lt;event&amp;gt;(Processed|Send))"
| eval _time=strptime(time,"%Y-%m-%d %H:%M:%S,%Q")
| eval {event}=_time
| stats values(Processed) as Processed values(Send) as Send by txid
| eval gap=Send-Processed&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 07 Nov 2021 17:22:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/find-time-gaps/m-p/573940#M200014</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-11-07T17:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: find time gaps</title>
      <link>https://community.splunk.com/t5/Splunk-Search/find-time-gaps/m-p/574146#M200097</link>
      <description>&lt;P&gt;Thank you for answer,&lt;/P&gt;&lt;P&gt;actually the main issue is find patterns like this:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-10-25 08:59:50,725 INFO CUS.AbCD-VW2-1234567890 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-10-25 08:59:50,726 INFO CUS.AbCD-VW2-1234567890 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-10-25 08:59:52,730 INFO CUS.AbCD-VW2-0987654321 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-10-25 08:59:52,735 INFO CUS.AbCD-VW2-0987654321 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 08:59:54,736 INFO CUS.AbCD-VW2-6478523699 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 08:59:54,736 INFO CUS.AbCD-VW2-6632587411 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 08:59:54,737 INFO CUS.AbCD-VW2-6333322222 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:54,725 INFO CUS.AbCD-VW2-1478523699 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:58,705 INFO CUS.AbCD-VW2-9632587411 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:59,800 INFO CUS.AbCD-VW2-3333322222 [FlowProcessorService] Packet Processed:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:59,805 INFO CUS.AbCD-VW2-9632587411 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:59,950 INFO CUS.AbCD-VW2-3333322222 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2021-10-25 08:59:59,955 INFO CUS.AbCD-VW2-1478523699 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 09:00:00,956 INFO CUS.AbCD-VW2-6632587411 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 09:00:00,956 INFO CUS.AbCD-VW2-6333322222 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;2021-10-25 09:00:00,956 INFO CUS.AbCD-VW2-6478523699 [AppClientManager] Send Packet&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;sometimes lots of&amp;nbsp;&lt;FONT color="#FF0000"&gt;Packet Processed &lt;FONT color="#000000"&gt;come and related&amp;nbsp;&lt;FONT color="#993366"&gt;Send Packet &lt;FONT color="#000000"&gt;stuck in queue, need to find them.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;here is the flow:&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;1-(Packet Processed) node1&lt;STRONG&gt;send&amp;nbsp;packet to node2&lt;/STRONG&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;2-node2&amp;nbsp;(return response to node1) &amp;gt; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;3-(Send Packet) node1 &lt;STRONG&gt;send&amp;nbsp;packet to another node 3&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#993366"&gt;&lt;FONT color="#000000"&gt;as you see couple of times continuously (Packet Processed).&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Its duration varies, actually this is a pattern or behavior.&lt;/P&gt;&lt;P&gt;is there any way to do this with splunk?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 07:46:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/find-time-gaps/m-p/574146#M200097</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2021-11-09T07:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: find time gaps</title>
      <link>https://community.splunk.com/t5/Splunk-Search/find-time-gaps/m-p/574151#M200099</link>
      <description>&lt;P&gt;I am not sure what you think is a pattern - the example I showed will allow you to determine the "time gaps" between packet processed and send packet messages for each transaction id (I am assuming that this is what the string beginning CUS is). You can then identify which of these are over your expected gap. Is this not what you are looking for?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 08:57:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/find-time-gaps/m-p/574151#M200099</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-11-09T08:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: find time gaps</title>
      <link>https://community.splunk.com/t5/Splunk-Search/find-time-gaps/m-p/574250#M200124</link>
      <description>&lt;P&gt;Actually i think about &lt;A href="https://splunkbase.splunk.com/app/2890/" target="_self"&gt;Splunk&lt;SPAN&gt;&amp;nbsp;Machine Learning Toolkit (MLTK)&lt;/SPAN&gt; &lt;/A&gt;or&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/MLApp/5.3.0/User/SmartOutlierAssistant" target="_self"&gt;outliner &lt;/A&gt;&lt;SPAN&gt;or &lt;/SPAN&gt;&lt;A href="https://www.splunk.com/en_us/blog/platform/what-s-new-in-the-splunk-machine-learning-toolkit-4-2.html" target="_self"&gt;density function&lt;/A&gt;&lt;SPAN&gt; may help us to detect these abnormal conditions.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;as I mentioned only extract duration not solve issue.&amp;nbsp;&lt;BR /&gt;FYI: sometimes might the&amp;nbsp;duration is high for some Proceed &amp;amp; Send and its normal,&amp;nbsp;but when couple of Proceed come and queued after a while Send appear this means something wrong,in this condition duration might be high or low.&amp;nbsp;&lt;BR /&gt;so high duration not resolve issue here.&lt;/P&gt;&lt;P&gt;Another idea is measure density of “Proceed” over the time due to “Send”.&lt;/P&gt;&lt;P&gt;any other idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 17:18:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/find-time-gaps/m-p/574250#M200124</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2021-11-09T17:18:21Z</dc:date>
    </item>
  </channel>
</rss>

