Splunk Search

How to retrieve the last occurrence of an event right before another event

lbentin
New Member

I have a log4j log as source on Splunk 6.2.2
As in the title, I would like to get the first event that matches a search before another event but don't know how to achieve this.
What I want to do is basically search for 'B', after matching, searching the first match for 'A' in backward direction (earlier in time) and print both raw lines.

Event A:

2018-02-19 09:28:31,332 [ INFO] {omissis} (omissis) - Opening and starting to process element. ID=23409432, type=3, location=/path/to/file.f

Event B:

2018-02-19 09:30:34,882 [ WARN] {omissis} (omissis) - Warning that should not be here and is related to the element loaded in event A.

Between 'A' and 'B' there is a non reproducible number of other log lines, time and events.

Thanks,
LB

0 Karma

Ayn
Legend
0 Karma
Get Updates on the Splunk Community!

Machine Learning - Assisted Adaptive Thresholding

Let’s talk thresholding. Have you set up static thresholds? Tired of static thresholds triggering false ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...