Hey, Thanks again for giving me your insight on this one. I did come across the bin command but thought the transaction might be better to try in this situation. As I am still learning the power a...
See more...
Hey, Thanks again for giving me your insight on this one. I did come across the bin command but thought the transaction might be better to try in this situation. As I am still learning the power and uses of many of the commands that can be used in Splunk, this does help me get a better understanding of how to use and when to use the transaction command. As you pointed out and is my true problem in this case, there are only two common/semi common variables I have between my two indexes, that being "_time" and "username". I have compared the raw logs from both indexes and it appears that at most, the print jobs are separated by 2 secs and I haven't seen any print jobs by the same user that have been closer than 10 seconds apart. But as to your point, I will make note that there could be some issue with my output if a user prints two jobs seconds apart from each other. As always, appreciate your input and clarification on my questions.