Splunk Search

_time from host

Path Finder

I have host A and B.Both of this host have different _time values.Can I use _time from Host A only?
How can i do this?
My purpose is to generate a timechart.

0 Karma


The time reference comes from each individual log entry. In order to relate the results for host A and B together, you would need to be performing some kind of joined search where you take results from host A as your principal data source, and then cross-relate to matching results from host B. How you do that depends on what the data is, and what the fixed relationship is between the two machines.

0 Karma


Give more details. Right now it's hard to understand your exact scenario. All events will have a _time value set - what do you mean by just using _time from a certain host? How will that be used for other events?

0 Karma