Splunk Search

_time from host

jimjohn
Path Finder

I have host A and B.Both of this host have different _time values.Can I use _time from Host A only?
How can i do this?
My purpose is to generate a timechart.

0 Karma

grijhwani
Motivator

The time reference comes from each individual log entry. In order to relate the results for host A and B together, you would need to be performing some kind of joined search where you take results from host A as your principal data source, and then cross-relate to matching results from host B. How you do that depends on what the data is, and what the fixed relationship is between the two machines.

0 Karma

Ayn
Legend

Give more details. Right now it's hard to understand your exact scenario. All events will have a _time value set - what do you mean by just using _time from a certain host? How will that be used for other events?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...