Splunk Search

How to retrieve the last occurrence of an event right before another event

lbentin
New Member

I have a log4j log as source on Splunk 6.2.2
As in the title, I would like to get the first event that matches a search before another event but don't know how to achieve this.
What I want to do is basically search for 'B', after matching, searching the first match for 'A' in backward direction (earlier in time) and print both raw lines.

Event A:

2018-02-19 09:28:31,332 [ INFO] {omissis} (omissis) - Opening and starting to process element. ID=23409432, type=3, location=/path/to/file.f

Event B:

2018-02-19 09:30:34,882 [ WARN] {omissis} (omissis) - Warning that should not be here and is related to the element loaded in event A.

Between 'A' and 'B' there is a non reproducible number of other log lines, time and events.

Thanks,
LB

0 Karma

Ayn
Legend
0 Karma
Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of Splunk APM’s and Splunk RUM’s streaming infrastructure in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...