Security

is it possible to get splunk to insert same event betweent he start and end time of the first record?

w344423
Explorer

Sample Data,

datetime starttime endtime id desc
1 2018-08-16 10:49:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2 2018-08-16 10:54:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
3 2018-08-16 11:20:06 2018-08-16 11:20:06 2018-08-16 11:24:05 STAFF-1006 Valid Card Entry
4 2018-08-16 11:24:05 2018-08-16 11:24:05 2018-08-23 10:16:53 STAFF-1006 Valid Card Exit
5 2018-08-23 10:16:53 2018-08-23 10:16:53 2018-08-23 10:40:40 STAFF-1006 Valid Card Entry
6 2018-08-23 10:40:40 2018-08-23 10:40:40 2018-08-27 12:58:54 STAFF-1006 Valid Card Exit
7 2018-08-27 12:58:54 2018-08-27 12:58:54 2018-08-27 13:12:31 STAFF-1006 Valid Card Entry
8 2018-08-27 13:12:31 2018-08-27 13:12:31 2018-08-30 16:11:05 STAFF-1006 Valid Card Exit
9 2018-08-30 16:11:05 2018-08-30 16:11:05 2018-08-30 16:14:47 STAFF-1006 Valid Card Entry
10 2018-08-30 16:14:47 2018-08-30 16:14:47 2018-09-05 15:16:00 STAFF-1006 Valid Card Exit

i would like to duplicate every event across multiple rows base on start and end time and each event will add 1 min to the current records starttime and once it hits the endtime it will go to the next records and perform the same job.

example
2018-08-16 10:49:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:50:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:51:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:52:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:53:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:55:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:56:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:57:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:58:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:59:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:00:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:01:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:02:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
... ... ...

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk cannot do that at index time. However, you can get similar results at search time using filldown.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...