Sample Data,
datetime starttime endtime id desc
1 2018-08-16 10:49:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2 2018-08-16 10:54:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
3 2018-08-16 11:20:06 2018-08-16 11:20:06 2018-08-16 11:24:05 STAFF-1006 Valid Card Entry
4 2018-08-16 11:24:05 2018-08-16 11:24:05 2018-08-23 10:16:53 STAFF-1006 Valid Card Exit
5 2018-08-23 10:16:53 2018-08-23 10:16:53 2018-08-23 10:40:40 STAFF-1006 Valid Card Entry
6 2018-08-23 10:40:40 2018-08-23 10:40:40 2018-08-27 12:58:54 STAFF-1006 Valid Card Exit
7 2018-08-27 12:58:54 2018-08-27 12:58:54 2018-08-27 13:12:31 STAFF-1006 Valid Card Entry
8 2018-08-27 13:12:31 2018-08-27 13:12:31 2018-08-30 16:11:05 STAFF-1006 Valid Card Exit
9 2018-08-30 16:11:05 2018-08-30 16:11:05 2018-08-30 16:14:47 STAFF-1006 Valid Card Entry
10 2018-08-30 16:14:47 2018-08-30 16:14:47 2018-09-05 15:16:00 STAFF-1006 Valid Card Exit
i would like to duplicate every event across multiple rows base on start and end time and each event will add 1 min to the current records starttime and once it hits the endtime it will go to the next records and perform the same job.
example
2018-08-16 10:49:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:50:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:51:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:52:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:53:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:55:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:56:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:57:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:58:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:59:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:00:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:01:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:02:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
... ... ...
Splunk cannot do that at index time. However, you can get similar results at search time using filldown
.