Security

is it possible to get splunk to insert same event betweent he start and end time of the first record?

w344423
Explorer

Sample Data,

datetime starttime endtime id desc
1 2018-08-16 10:49:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2 2018-08-16 10:54:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
3 2018-08-16 11:20:06 2018-08-16 11:20:06 2018-08-16 11:24:05 STAFF-1006 Valid Card Entry
4 2018-08-16 11:24:05 2018-08-16 11:24:05 2018-08-23 10:16:53 STAFF-1006 Valid Card Exit
5 2018-08-23 10:16:53 2018-08-23 10:16:53 2018-08-23 10:40:40 STAFF-1006 Valid Card Entry
6 2018-08-23 10:40:40 2018-08-23 10:40:40 2018-08-27 12:58:54 STAFF-1006 Valid Card Exit
7 2018-08-27 12:58:54 2018-08-27 12:58:54 2018-08-27 13:12:31 STAFF-1006 Valid Card Entry
8 2018-08-27 13:12:31 2018-08-27 13:12:31 2018-08-30 16:11:05 STAFF-1006 Valid Card Exit
9 2018-08-30 16:11:05 2018-08-30 16:11:05 2018-08-30 16:14:47 STAFF-1006 Valid Card Entry
10 2018-08-30 16:14:47 2018-08-30 16:14:47 2018-09-05 15:16:00 STAFF-1006 Valid Card Exit

i would like to duplicate every event across multiple rows base on start and end time and each event will add 1 min to the current records starttime and once it hits the endtime it will go to the next records and perform the same job.

example
2018-08-16 10:49:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:50:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:51:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:52:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:53:49 2018-08-16 10:49:49 2018-08-16 10:54:13 STAFF-1006 Valid Card Entry
2018-08-16 10:55:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:56:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:57:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:58:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 10:59:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:00:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:01:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
2018-08-16 11:02:13 2018-08-16 10:54:13 2018-08-16 11:20:06 STAFF-1006 Valid Card Exit
... ... ...

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk cannot do that at index time. However, you can get similar results at search time using filldown.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...