Hi all,
I'm trying to figure out how to get my hands on a list of IDs which are determined by referring to three events. I have to not use things such as join, transaction, or sub-search due to the event limits involved.
Specifically, I have:
The reason I need to use Event A rather than just look at Event B and Event C is because there are numerous occurrences of Event B that are unrelated, so I first have to ensure they can be associated with an Event A.
TLDR! I need the list of personId values that come from Event C, but first I need to make sure they are associated with Event A and Event B — the challenge being there is no one value contained by all three.
Try something like this
-- your search with all types of events
| eventstats values(correlationId) as correlationId by req_id
| eventstats values(personId) as personId by correlationId
Event A should now have all three ids
Try something like this
-- your search with all types of events
| eventstats values(correlationId) as correlationId by req_id
| eventstats values(personId) as personId by correlationId
Event A should now have all three ids
If it helps, here is roughly what I did to achieve this using transaction, but because I need to run it over months this very quickly exhausts Splunk's event limits:
(Event A)
OR (Event B)
OR (Event C)
| transaction correlationId
| where Event B OR Event C
| transaction req_id
| where Event C
| where personId!=""
| stats count by personId