Splunk Search

Find events in a different index related by time

splunkranger
Path Finder

I need to find events in Index B that happened withing 5 minutes of events in Index A.

Unfortunately I do not have anyway to join them other than time ranges. Can you help me figure this out?

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Try this:

index=A something | localize timebefore=5m timeafter=5m | map search="search earliest=$starttime$ latest=$endtime$ index=B"

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Try this:

index=A something | localize timebefore=5m timeafter=5m | map search="search earliest=$starttime$ latest=$endtime$ index=B"

splunkranger
Path Finder

That worked! Thank you!!!!

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...