Splunk Search

How to filter out events before/after a specific event

tanyongjin
Explorer

Hi,

I want to filter out an event that occurs just before/after all the occurrence of a specific event, 'X". How can I do it?

If I want to aggregate them out to get some statistics or plot a graph, how can I do it too?

Tags (1)
0 Karma

DalJeanis
Legend

You will have to be much more specific about your data, because the answer to your question depends on how you are identifying the event X, and how you are identifying the events A and Z that you want filtered out.

So, please post an example (non confidential, of course) of event X, and an example of the events you might like to filter out. If you describe in plain language the rationale for omitting them, that can help us meet your need as well.

0 Karma

tanyongjin
Explorer

Here, X is an exact requirement provided to me. X is an access to an specific API, which for confidentiality, I am unable to provide an example of it.

So if a user uses A, then proceeds to X then to Z. We know that the flow goes from A -> X -> Z.

From this information, I would like to find out for all the users in the system, what is their "A" and "Z". Then determine if access to "A" and "Z" are related to the usage of X. Thus, I can report this finding up to my superior and for them to determine what could be missing in the implementation of X, which causes users to access "A" and "Z", which in turn can help improve X.

Thank you.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...