Splunk Search

Splunk 7 / Win2012r2: Retrieve Tag's Value, based on another Tag's Value & Time

htkwan
Path Finder

Hello,
I'm new to Splunk. Need some advice, I need to do as follows:
Pls. see attached, the sample.
Tag 1 = ProductionState: 0 (for 30 sec), 1 (for 90 secs), then repeat. An event is generated every 1 sec (i.e. TagAlias=ProductionState, Value=<0 or 1>)

Tag 2: WireTensionLeft: 0 (for 1 sec), 10 (for 1 sec), …, 100 (for 1 sec), then repeat. An event is generated every 1 sec (i.e. TagAlias=WireTensionLeft, Value=<0,10, ..., 100, 0,...>)

Requirement
1.Retrieve Tag1 – Value at 10 sec, 20 sec, & 75 sec, when Tag2 – Value = 1

Pls. advise. Thanks

0 Karma
Get Updates on the Splunk Community!

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...