Splunk Search

How to retrieve the last occurrence of an event right before another event

lbentin
New Member

I have a log4j log as source on Splunk 6.2.2
As in the title, I would like to get the first event that matches a search before another event but don't know how to achieve this.
What I want to do is basically search for 'B', after matching, searching the first match for 'A' in backward direction (earlier in time) and print both raw lines.

Event A:

2018-02-19 09:28:31,332 [ INFO] {omissis} (omissis) - Opening and starting to process element. ID=23409432, type=3, location=/path/to/file.f

Event B:

2018-02-19 09:30:34,882 [ WARN] {omissis} (omissis) - Warning that should not be here and is related to the element loaded in event A.

Between 'A' and 'B' there is a non reproducible number of other log lines, time and events.

Thanks,
LB

0 Karma

Ayn
Legend
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...