<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pair events 4778 &amp;amp; 4779 in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Pair-events-4778-amp-4779/m-p/579623#M201966</link>
    <description>&lt;P&gt;How do I pair events 4778 &amp;amp; 4779 for the same Logon_ID when I have multi 4778 and multi 4779?&lt;BR /&gt;I would like to pair the first 4779 event (disconnect) with the first 4778 event (reconnect) and than do the same for the second 4779 event with the second 4778 event etc'&lt;/P&gt;</description>
    <pubDate>Thu, 30 Dec 2021 17:10:15 GMT</pubDate>
    <dc:creator>eranhauser</dc:creator>
    <dc:date>2021-12-30T17:10:15Z</dc:date>
    <item>
      <title>Pair events 4778 &amp; 4779</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Pair-events-4778-amp-4779/m-p/579623#M201966</link>
      <description>&lt;P&gt;How do I pair events 4778 &amp;amp; 4779 for the same Logon_ID when I have multi 4778 and multi 4779?&lt;BR /&gt;I would like to pair the first 4779 event (disconnect) with the first 4778 event (reconnect) and than do the same for the second 4779 event with the second 4778 event etc'&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 17:10:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Pair-events-4778-amp-4779/m-p/579623#M201966</guid>
      <dc:creator>eranhauser</dc:creator>
      <dc:date>2021-12-30T17:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Pair events 4778 &amp; 4779</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Pair-events-4778-amp-4779/m-p/579707#M201992</link>
      <description>&lt;P&gt;Sounds like you are looking for&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/SearchReference/Transaction" target="_blank"&gt;transaction&lt;/A&gt;. &amp;nbsp;Something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| transaction Logon_ID startswith=Event_ID==4778 endswith=Event_ID==4779&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 01 Jan 2022 05:38:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Pair-events-4778-amp-4779/m-p/579707#M201992</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-01-01T05:38:11Z</dc:date>
    </item>
  </channel>
</rss>

