Security

is it possible to get splunk to insert same event betweent he start and end time of the first record?

w344423
Explorer

Sample Data,

datetime starttime endtime id desc
1 2018-08-16 10:49:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2 2018-08-16 10:54:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
3 2018-08-16 11:20:06 2018-08-16 11:20:06 2018-08-16 11:24:05 STAFF-1006 Valid Card Entry
4 2018-08-16 11:24:05 2018-08-16 11:24:05 2018-08-23 10:16:53 STAFF-1006 Valid Card Exit
5 2018-08-23 10:16:53 2018-08-23 10:16:53 2018-08-23 10:40:40 STAFF-1006 Valid Card Entry
6 2018-08-23 10:40:40 2018-08-23 10:40:40 2018-08-27 12:58:54 STAFF-1006 Valid Card Exit
7 2018-08-27 12:58:54 2018-08-27 12:58:54 2018-08-27 13:12:31 STAFF-1006 Valid Card Entry
8 2018-08-27 13:12:31 2018-08-27 13:12:31 2018-08-30 16:11:05 STAFF-1006 Valid Card Exit
9 2018-08-30 16:11:05 2018-08-30 16:11:05 2018-08-30 16:14:47 STAFF-1006 Valid Card Entry
10 2018-08-30 16:14:47 2018-08-30 16:14:47 2018-09-05 15:16:00 STAFF-1006 Valid Card Exit

i would like to duplicate every event across multiple rows base on start and end time and each event will add 1 min to the current records starttime and once it hits the endtime it will go to the next records and perform the same job.

example
2018-08-16 10:49:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:50:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:51:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:52:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:53:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:55:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:56:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:57:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:58:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:59:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:00:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:01:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:02:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
... ... ...

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk cannot do that at index time. However, you can get similar results at search time using filldown.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...