Splunk Search

How do you bucket two events starting using a timespan that starts with the first event?

rkondeti3
Explorer

My question is a mix of using the transaction command with the bin command.

What I would like to achieve is capturing when 2 consecutive POST requests are made in proxy logs within two seconds of each other. Straight up using | _bin span=2s misses out on events that might happen during odd seconds.

Essentially, I want the two second timer to start when the first event occurs, and then looks for the next event (another POST request), within two seconds.

Is there a feasible way to achieve what I'm asking for? Or am I not making much sense?

0 Karma

adonio
Ultra Champion

when you say consecutive, do you mean that there is no other events in between those 2 POST events?
can you share some masked data sample?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...