I have a query to fetch account create endpoint and errors after
(index=foo "account/create") OR (index=bar ERROR)
But right part of OR would return all errors in time frame.
Is it possible to fetch events from bar index in 5 seconds after event in foo index?
I found Localize function, but looks like it works only in same index
You can do that with the map command.
(index=foo "account/create")
| eval earliest=_time, latest=_time + 5
| map search="index=bar ERROR earliest=$earliest$ latest=$latest$"