Splunk Search

How to retrieve the last occurrence of an event right before another event

lbentin
New Member

I have a log4j log as source on Splunk 6.2.2
As in the title, I would like to get the first event that matches a search before another event but don't know how to achieve this.
What I want to do is basically search for 'B', after matching, searching the first match for 'A' in backward direction (earlier in time) and print both raw lines.

Event A:

2018-02-19 09:28:31,332 [ INFO] {omissis} (omissis) - Opening and starting to process element. ID=23409432, type=3, location=/path/to/file.f

Event B:

2018-02-19 09:30:34,882 [ WARN] {omissis} (omissis) - Warning that should not be here and is related to the element loaded in event A.

Between 'A' and 'B' there is a non reproducible number of other log lines, time and events.

Thanks,
LB

0 Karma

Ayn
Legend
0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...