Knowledge Management

Find the earliest event matching startswith using transaction

nkgon
New Member

So I have a log with multiple VPN connection, and some of them reconnect to the same session multiple times a day for example:

08:02:00- User A login
08:10:12- User A login, replace old connection
08:12:13- User A login, replace old connection
08:15:13- User A logout, disconnected

when I use transaction , splunk only get the events at 08:15:13 and 08:12:13 , but I want it to get the earliest event at 08:02:00, are there any way to achieve that ?

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Ignore the replace old connection events in your startswith condition.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...