splunk query neighboring events

splunk query neighboring events

  1. you should be able to -A or -B (but not both) using the transaction command
  2. equivalent of -B .... | transaction endswith=(<search that matches the event of interest>) maxevents=<number of events in txn>
  3. equivalent of -A
  4. .... | transaction startswith=(<search that matches the event of interest>) maxevents=<number of events in txn>

see my example, it works very well. 

About jsdom

leading software engineer
This entry was posted in Uncategorized. Bookmark the permalink.

Leave a comment