Splunk Search

How to search two indexes to find if an event in index B does not occur within certain time range of an event in index A?

patelaa
Explorer

I hope the following makes sense...I have two indexes for separate application logs, index A and index B. I need help writing a search that will show me if a certain event in index B does not occur within 24 hours of an event in index A.

The search to find the event in index A is:

index=indexA sourcetype=sourcetype Network_Address="1.1.1.1" OR Network_Address="2.2.2.2" OR Network_Address="3.3.3.3" 
| stats values(src) values(time) by user

The search to find the event in index B is:

index=indexB "eventCode" | stats values(id) values(time) AS id by user

So basically I want the search to show me all users who have an event in index A, along with the src and time from each event, but don't have an event in index B within 24 hours of the index A event.

Tags (3)
1 Solution

mreynov_splunk
Splunk Employee
Splunk Employee

I would suggest to use outputlookup to store results of the first query, then do the second search and use eval to make the calculation

View solution in original post

mreynov_splunk
Splunk Employee
Splunk Employee

I would suggest to use outputlookup to store results of the first query, then do the second search and use eval to make the calculation

patelaa
Explorer

Using mreynov's suggestion I piped the search in index A to a lookup table then used the following search to get my desired results

|inputlookup lookUpName.csv
| search NOT [search index=indexB "eventCode"
| fields user]

Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...