Splunk Search
Highlighted

How to search for overlapping events that occurred on the same host?

Explorer

Given the Splunk result set in the attached screenshot, I'd like to formulate a search that finds all overlapping events that occurred on the same host. Many thanks!

0 Karma
Highlighted

Re: How to search for overlapping events that occurred on the same host?

Splunk Employee
Splunk Employee

You could use the transaction command, for example:

.... | transaction host

0 Karma
Highlighted

Re: How to search for overlapping events that occurred on the same host?

Explorer

This returns no results.

0 Karma
Highlighted

Re: How to search for overlapping events that occurred on the same host?

New Member

What about this?

| stats values(MessageKey) by host
Or
| chart count over host by MessageKey usenull=f

0 Karma