Splunk Search

How to find the most recent event for a user preceding some other event

MatMeredith
Path Finder

I have a set of user activity logs, each of which identifies an event-type and a user-id. One possible event-type is "Exception" and when a user hits an "Exception" I want to know what other event type most commonly precedes it for the user. Specifically I'd like a table that shows me how often the most recent previous event is X, Y, Z etc.

I'm struggling to see how to do this. Can anyone help please?

Many thanks!

Tags (1)

martin_mueller
SplunkTrust
SplunkTrust

You could use streamstats to append the previous event to the current event, and then use that to build your table.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Try something like this:

... | streamstats current=f window=1 last(eventtype) as other_eventtype by userid
0 Karma

MatMeredith
Path Finder

Thanks for the answer, but could you offer any more detail please as I'm still not clear how I would do that? E.g. suppose in a very simple example I have

  • userid 1, eventtype A
  • ...
  • userid 2, eventtype B
  • ...
  • userid 1, eventtype "Exception"
  • ...
  • userid 1, eventtype C
  • ...
  • userid 1, eventtype "Exception"
  • ...
  • userid 2, eventtype "Exception"

Here I'd want to see that 1/3 of the time the preceding event was A, 1/3 of the time it was B and 1/3 of the time it was C...

0 Karma
Get Updates on the Splunk Community!

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...