<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EventCode Subsearch in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/EventCode-Subsearch/m-p/678381#M231986</link>
    <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901" target="_blank"&gt;@yuanliu&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;Is there a way to say if EventCode=70 look upstream for&amp;nbsp;EventCode=250 and join User?&amp;nbsp; I am only trying to capture who created the event.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Feb 2024 20:41:58 GMT</pubDate>
    <dc:creator>jeradb</dc:creator>
    <dc:date>2024-02-22T20:41:58Z</dc:date>
    <item>
      <title>EventCode Subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EventCode-Subsearch/m-p/678357#M231980</link>
      <description>&lt;P&gt;I have an application that I am trying to monitor.&amp;nbsp; There is a specific event code for when the tool is opened to modify the tool (EventCode=250).&amp;nbsp; There is an EventCode for when it is closed&amp;nbsp;(EventCode=100).&amp;nbsp; These two codes display a user name, but the events between them do not.&amp;nbsp; How can I write a search to look for these two events then display the changes between them with the username who completed the change?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| from datamodel:P3 | search EventCode=250 OR 100 OR 70 OR 80
| eval user = coalesce(User, Active_User)
| eval Event_Time=strftime(_time,"%m/%d/%y %I:%M:%S %P")

| table Event_Time, host,user,Device_Added,Device_SN,Device_ID,EventCode, EventDescription&lt;/LI-CODE&gt;&lt;P&gt;Event_Time&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; host&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; user&amp;nbsp; &amp;nbsp; &amp;nbsp; Device_Added&amp;nbsp; &amp;nbsp; &amp;nbsp; Device_SN&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Device_ID&amp;nbsp; &amp;nbsp; &amp;nbsp; EventCode&amp;nbsp;&lt;BR /&gt;02/22/24 08:49:44 am Test-Com&amp;nbsp; &amp;nbsp;xxxxx&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;100&lt;BR /&gt;02/21/24 03:59:12 pm Test-Com&amp;nbsp; &amp;nbsp;xxxxx&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 250&lt;BR /&gt;02/21/24 03:56:08 pm Test-Com&amp;nbsp; &amp;nbsp;xxxxx&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 100&lt;BR /&gt;02/21/24 03:56:00 pm Test-Com&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; USB 1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;12345&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; PID_1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;70&amp;nbsp;&lt;BR /&gt;02/21/24 03:56:00 pm Test-Com&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; USB 2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 6789&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; PID_2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;70&amp;nbsp;&lt;BR /&gt;02/21/24 03:51:10 pm Test-Com&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; USB 1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;12345&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; PID_1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp;&lt;BR /&gt;02/21/24 03:50:44 pm Test-Com&amp;nbsp; &amp;nbsp; &amp;nbsp;xxxxx&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 250&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 16:27:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EventCode-Subsearch/m-p/678357#M231980</guid>
      <dc:creator>jeradb</dc:creator>
      <dc:date>2024-02-22T16:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: EventCode Subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EventCode-Subsearch/m-p/678362#M231981</link>
      <description>&lt;P&gt;If the illustrated fields are all you have, the only link between 250 -&amp;gt; 100 (with user) and the rest of events (without) is host. &amp;nbsp;I highly doubt if this can be sufficient to determine what a user have done between 250 and 100, unless this tool is strictly single-user and no other things can generate any of these events.&lt;/P&gt;&lt;P&gt;If the tool is single-user only, you can use transaction to group these events together, like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| transaction host startswith="EventCode=250" endswith="EventCode=100"&lt;/LI-CODE&gt;&lt;P&gt;Once transactions are established, you can then glean completed transactions for event codes that are not 250 and 100. &amp;nbsp;For example,&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| transaction host startswith="EventCode=250" endswith="EventCode=100"​
| stats values(EventCode) as EventCode values(user) as user by host
| eval EventCode = mvfilter(NOT EventCode IN ("250", "100"))&lt;/LI-CODE&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 17:26:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EventCode-Subsearch/m-p/678362#M231981</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-02-22T17:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: EventCode Subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EventCode-Subsearch/m-p/678381#M231986</link>
      <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901" target="_blank"&gt;@yuanliu&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;Is there a way to say if EventCode=70 look upstream for&amp;nbsp;EventCode=250 and join User?&amp;nbsp; I am only trying to capture who created the event.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 20:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EventCode-Subsearch/m-p/678381#M231986</guid>
      <dc:creator>jeradb</dc:creator>
      <dc:date>2024-02-22T20:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: EventCode Subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/EventCode-Subsearch/m-p/678395#M231989</link>
      <description>&lt;P&gt;This is very much a question of efficiency. &amp;nbsp;If you have a relatively small number of event 70 in a short period of time, but event 250 was some long time ago, using subsearch would be more efficient than retrieving both types of events for a long period of time.&lt;/P&gt;&lt;P&gt;You also need to tell us which EventCode's give you User, which give you Active_User. &amp;nbsp;Assuming that EventCode 250 gives you Active_User but 70 gives you User, you can do something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| from datamodel:P3
| search EventCode=250 earliest=-1mon ``` earliest value for demonstration purpose only ```
    [from datamodel:P3
    | search EventCode=70 earliest=-1h ``` earliest value for demonstration purpose only ```
    | stats values(User) as Active_User ``` assuming User is present in EventCode 70 to matche Active_User in EventCode 250 ]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 21:28:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/EventCode-Subsearch/m-p/678395#M231989</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-02-22T21:28:50Z</dc:date>
    </item>
  </channel>
</rss>

