Splunk Search

Splunk for analyzing Logs - looking for Big time gaps graph.

Arkowski
New Member

Hi!

I have a log that looks more or less like this:

 

'H 16-Sep-2021 10:57:03.084;   0:< 
 Jrn.Directive "WindowSize"  _
         , "[TMM_TEMP_HKLS_R20_V08x.rte]", "Sheet: 00 - Starting View" _
         , 1176, 922
																																					  
																   
'H 16-Sep-2021 10:57:03.251;   0:< 
Jrn.Directive "ScreenResolution"  _
        , 324, 1200
'H 16-Sep-2021 10:57:03.251;   0:< 
Jrn.Directive "ProjToPage"  _
        , "[TMM_TEMP_HKLS_R20_V08x.rte]", "Sheet: 00 - Starting View" _
        , 890.19441375881252 _
        , 890.19441375881252, 0.00000000000000, 0.00000000000000 _
        , 0.00000000000000, 890.19441375881252, 0.00000000000000 _
        , 0.00000000000000, 0.00000000000000, 890.19441375881252 _
        , 0.00000000000000, 0.00000000000000, 0.00000000000000
'H 16-Sep-2021 10:57:03.252;   0:< 

 

 

I am looking for something that would help me to analyze it and find big time gaps between events. Something like a graph that would indicate how big gaps occurred over time.

I just need something that would let me not look for those event by event or with notepad (logs tend to be big). I am completely new with Splunk, someone just let me know this is easily done with it. Thanks for any help.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...