Splunk Search

Tabulate frequency of all events within X events of found event

john_loch
Explorer

Hi all,

This is slightly tricky - well for me anyways..

I have an index where a key event is occuring. I need to be able to examine the 5 events prior to and after the key event (irrespective of time) per host, and tabulate a count of each event type (by type i mean the string that appears in the log entry).. so if we have 7 distinct event types surrounding all instances of the key event, then we would see a table with 7 rows, showing the event and a count of occurances.

The idea is to use proximal analysis to get a bead on possible causal relationship. I'm pretty sure this is a common practice - but after hunting around I can't find a reference to it anywhere..

Would much appreciate any Ninja feedback..

Thx.

Tags (1)
0 Karma

woodcock
Esteemed Legend
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...