I have a log4j log as source on Splunk 6.2.2
As in the title, I would like to get the first event that matches a search before another event but don't know how to achieve this.
What I want to do is basically search for 'B', after matching, searching the first match for 'A' in backward direction (earlier in time) and print both raw lines.
Event A:
2018-02-19 09:28:31,332 [ INFO] {omissis} (omissis) - Opening and starting to process element. ID=23409432, type=3, location=/path/to/file.f
Event B:
2018-02-19 09:30:34,882 [ WARN] {omissis} (omissis) - Warning that should not be here and is related to the element loaded in event A.
Between 'A' and 'B' there is a non reproducible number of other log lines, time and events.
Thanks,
LB
Have you checked the answer here: https://answers.splunk.com/answers/150509/how-to-get-events-around-identified-event.html