Splunk Search

How to find event between two time fields?

bt149
Path Finder

I have logs (Azure logs) that have two time fields, StartTime and ExpirationTime.
Example:
index=azure sourcetype=my_sourcetype
| table StartTime ExpirationTime role user

I want to take the user and see if the user had a failed login attempt in another index / sourcetype between the two time fields StartTime and ExpirationTime.

Any help would be greatly appreciated.

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

You could use the results of this search as argument to another one by using subsearch but it's usually better to obtain the same result by other means. I think I'd try to get the combined results from both indexes and then try to group them with stats to find what you're looking for but for that you'd have to be a bit more elaborate as to what you have in and want from that other index.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...