Splunk Search

How to search two events that occurred right before a specific event showing a certain error to analyze what happened?

chris1
Explorer

Hello,

When I search for some events (i.e index=main *password fail), I want to get the events with two lines before and after from source. In this way, it will help me to analyze why it happened. I know the way to go to > then Event action > show source option. But I want to get those details in my search result itself?

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!