I want to do a specific string search, say "mary had a little lamb" and have it return the results including the 5 lines previous and the 5 lines after.
I have seen some (too complex to believe) results here, but all near 10 years old. Is there a more recent, simpler way to do this? It is a simple switch in grep.
index=yours [search "mary had a little lamb" | eval earliest=relative_time(_time,"-5s"), latest=relative_time(_time,"+5s") | fields earliest latest | format]
Unlike grep, you can only handle it in time.