Please help me on below things: Requirements: Once 3 events meets, immediately next event should published.if event is not published after 5 min ,need alert. Example : We have one customerno.for the customer number ,I have to search whether 3 events meets logs available in the splunk log or not Ex: index= 1 source type ="abc" "s1 event received" and "s2 event received" and "s3 event received" When I search above query ,I will be getting like( format as below ) S1 received for 12345 customer,name=abz S2 received for 12345 customer,name = abz S3 received for 12345 customer,name =abz If for one customer,all 3 event are met,next i want to search "created" message available in the splunk for same customer (12345) Here "created" message index and source type is different If "created" message not available for 12345 customer no after 5 min once all 3 events meets,I need alert with customer no.pls help on this query..if "created" message available after 5 min also need capture customer number. Fyi : if we received "created" message in the log ,sample log will be (json format ) Log : created :{"customer no" : "12345",name :"kanunam"} like that. Please please help me on search query.
... View more