I have two related sets of data: Errors and CalcRun. The relationship in SQl speak is Many Errors to a CalcRun. When listing an error or set of errors I need to establish the appropriate CalcRun based on the time stamp.
Required 1 table Splunk output results from these two data inputs:
TIME: ERROR: CALCRUN:
10:12 error1 CalcRunB (error after 10:01 & before 10:40 hence B)
10:23 error2 CalcRunB (error after 10:01 & before 10:40 hence B)
10:34 error3 CalcRunB (error after 10:01 & before 10:40 hence B)
10:45 error4 CalcRunC (error after 10:40 & before 10:50 hence C)
10:56 error5 CalcRunD (error after10:50 & no more runs hence D)
This is easy to do in SQL with a cursor, any guidance on how to do this in splunk?