Splunk Search

Time matching w/ a +/- 5 min window

cquinney
Communicator

Greetings Splunkers,

I have a lookup file that has a list of set jobs with a frequency timestamp (e.g. Mon-Fri @ 3:30) of when the job should be seen within Splunk.  I'm wanting to create an eval that will allow me to match the index time of an event/job with its frequency timestamp.

The dilemma I'm having is incorporating a +/- 5 min time span into the matching criteria.  Any assistance in figuring this out would be greatly appreciated.

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
| eval start=computedTime - 300, end=computedTime + 300
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The +/- 5 minute bit is easy - just add or subtract 300 seconds from the computed timestamp.  IMO, the hard part is converting "Mon-Fri @ 3:30" into a timestamp.

---
If this reply helps you, Karma would be appreciated.
0 Karma

cquinney
Communicator

Hi  @richgalloway ,

Can you possibly provide an example of how you'd incorporate your suggestion into the eval?  Thank you.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
| eval start=computedTime - 300, end=computedTime + 300
---
If this reply helps you, Karma would be appreciated.
0 Karma

cquinney
Communicator

Hi @richgalloway 

Thank you for the advice, I ended up incorporating your suggestion into my query as such:

| eval TimeMatch=if(((_time >= _time-300 OR _time <= _time+300) AND _time=ExptectedTime), "Match", "No Match")

This gave me the results I was hoping for.  Thank you again!

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...