<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get all events between two events? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618438#M214942</link>
    <description>&lt;P&gt;I dont have specific identifier to match it...But I am looking get all the events between them and then a calculation on them&lt;/P&gt;</description>
    <pubDate>Wed, 26 Oct 2022 16:50:15 GMT</pubDate>
    <dc:creator>vrmandadi</dc:creator>
    <dc:date>2022-10-26T16:50:15Z</dc:date>
    <item>
      <title>How to get all events between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618427#M214935</link>
      <description>&lt;P&gt;I have the following events.I am trying to get all the events between START and END of a job (inclusive).For instance the below job 51060 has 3 events in between...I am trying to a transaction command but I dont get the events in between.I only get the start and end event&lt;BR /&gt;&lt;BR /&gt;| transaction startswith="START" endswith="END"&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;2022-10-21T23:26:14.075003-07:00&lt;/SPAN&gt;&amp;nbsp;xyz&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;slurm-epilog:&lt;/SPAN&gt; &lt;SPAN class=""&gt;END&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;user=svc&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;job=51060&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;2022-10-21T20:15:16.914838-07:00&lt;/SPAN&gt; xyz&amp;nbsp;&lt;SPAN class=""&gt;kernel:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;52023.042550&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;NVRM:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Xid&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;PCI:&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;119&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;pid=16378&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;name=cache_mgr_main&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Timeout&lt;/SPAN&gt; &lt;SPAN class=""&gt;waiting&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;RPC&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt; &lt;SPAN class=""&gt;GSP&lt;/SPAN&gt;&lt;SPAN&gt;! &lt;/SPAN&gt;&lt;SPAN class=""&gt;Expected&lt;/SPAN&gt; &lt;SPAN class=""&gt;function&lt;/SPAN&gt; &lt;SPAN class=""&gt;76&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;GSP_RM_CONTROL&lt;/SPAN&gt;&lt;SPAN&gt;) (&lt;/SPAN&gt;&lt;SPAN class=""&gt;0x20808513&lt;/SPAN&gt; &lt;SPAN class=""&gt;0x598&lt;/SPAN&gt;&lt;SPAN&gt;).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;2022-10-21T20:13:46.890841-07:00&lt;/SPAN&gt; xyz&amp;nbsp;&lt;SPAN class=""&gt;kernel:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;51933.011964&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;NVRM:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Xid&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;PCI:&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;119&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;pid=16378&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;name=cache_mgr_main&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Timeout&lt;/SPAN&gt; &lt;SPAN class=""&gt;waiting&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;RPC&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt; &lt;SPAN class=""&gt;GSP&lt;/SPAN&gt;&lt;SPAN&gt;! &lt;/SPAN&gt;&lt;SPAN class=""&gt;Expected&lt;/SPAN&gt; &lt;SPAN class=""&gt;function&lt;/SPAN&gt; &lt;SPAN class=""&gt;76&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;GSP_RM_CONTROL&lt;/SPAN&gt;&lt;SPAN&gt;) (&lt;/SPAN&gt;&lt;SPAN class=""&gt;0x20808513&lt;/SPAN&gt; &lt;SPAN class=""&gt;0x598&lt;/SPAN&gt;&lt;SPAN&gt;).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;2022-10-21T20:12:16.866833-07:00&lt;/SPAN&gt; xyz&amp;nbsp;&lt;SPAN class=""&gt;kernel:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;51842.981401&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;NVRM:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Xid&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;PCI:&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;119&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;pid=16378&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;name=cache_mgr_main&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;Timeout&lt;/SPAN&gt; &lt;SPAN class=""&gt;waiting&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;RPC&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt; &lt;SPAN class=""&gt;GSP&lt;/SPAN&gt;&lt;SPAN&gt;! &lt;/SPAN&gt;&lt;SPAN class=""&gt;Expected&lt;/SPAN&gt; &lt;SPAN class=""&gt;function&lt;/SPAN&gt; &lt;SPAN class=""&gt;76&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;GSP_RM_CONTROL&lt;/SPAN&gt;&lt;SPAN&gt;) (&lt;/SPAN&gt;&lt;SPAN class=""&gt;0x20808513&lt;/SPAN&gt; &lt;SPAN class=""&gt;0x598&lt;/SPAN&gt;&lt;SPAN&gt;).&lt;BR /&gt;&lt;SPAN class=""&gt;2022-10-21T19:17:25.710875-07:00&lt;/SPAN&gt; xyz&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;slurm-prolog:&lt;/SPAN&gt; &lt;SPAN class=""&gt;START&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;user=svc&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;job=51060&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 15:48:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618427#M214935</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2022-10-26T15:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to get all events between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618435#M214939</link>
      <description>&lt;P&gt;Is there any identifier that can tie the 3 middle events together with the start or end event or are you looking for all events between start and end?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 16:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618435#M214939</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-10-26T16:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to get all events between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618438#M214942</link>
      <description>&lt;P&gt;I dont have specific identifier to match it...But I am looking get all the events between them and then a calculation on them&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 16:50:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618438#M214942</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2022-10-26T16:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to get all events between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618443#M214947</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "\:\s(?&amp;lt;event_type&amp;gt;END|START)\s"
| transaction startswith=(event_type="START") endswith=(event_type="END")&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 26 Oct 2022 17:00:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618443#M214947</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-10-26T17:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to get all events between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618453#M214951</link>
      <description>&lt;P&gt;Doesnt give what I need...it just gives start and end events&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 18:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618453#M214951</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2022-10-26T18:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to get all events between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618454#M214952</link>
      <description>&lt;P&gt;Transaction will give you an output of unique values for each field -- are you sure you're only seeing start and end events?&lt;BR /&gt;&lt;BR /&gt;Try this as a test:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;base_search&amp;gt;
| rex "\:\s(?&amp;lt;event_type&amp;gt;END|START)\s"
| eval events="[".event_time."] : "._raw
| transaction startswith=(event_type="START") endswith=(event_type="END")
| table events&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 18:18:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618454#M214952</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-10-26T18:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to get all events between two events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618455#M214953</link>
      <description>&lt;P&gt;Yes I only see two events per transaction which has start and end but dont see any events like below&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;2022-10-21T20:15:16.914838-07:00&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;xyz&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;kernel:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;52023.042550&lt;/SPAN&gt;&lt;SPAN&gt;]&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;NVRM:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Xid&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;PCI:&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;119&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;pid=16378&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;name=cache_mgr_main&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Timeout&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;waiting&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;for&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;RPC&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;from&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;GSP&lt;/SPAN&gt;&lt;SPAN&gt;!&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Expected&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;function&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;76&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;GSP_RM_CONTROL&lt;/SPAN&gt;&lt;SPAN&gt;) (&lt;/SPAN&gt;&lt;SPAN class=""&gt;0x20808513&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;0x598&lt;/SPAN&gt;&lt;SPAN&gt;).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;2022-10-21T20:13:46.890841-07:00&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;xyz&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;kernel:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;51933.011964&lt;/SPAN&gt;&lt;SPAN&gt;]&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;NVRM:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Xid&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;PCI:&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;119&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;pid=16378&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;name=cache_mgr_main&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Timeout&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;waiting&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;for&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;RPC&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;from&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;GSP&lt;/SPAN&gt;&lt;SPAN&gt;!&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Expected&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;function&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;76&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;GSP_RM_CONTROL&lt;/SPAN&gt;&lt;SPAN&gt;) (&lt;/SPAN&gt;&lt;SPAN class=""&gt;0x20808513&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;0x598&lt;/SPAN&gt;&lt;SPAN&gt;).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;2022-10-21T20:12:16.866833-07:00&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;xyz&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;kernel:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;51842.981401&lt;/SPAN&gt;&lt;SPAN&gt;]&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;NVRM:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Xid&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;PCI:&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;119&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;pid=16378&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;name=cache_mgr_main&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 18:21:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-all-events-between-two-events/m-p/618455#M214953</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2022-10-26T18:21:18Z</dc:date>
    </item>
  </channel>
</rss>

