Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Create a search based on prior search timestamps

$
0
0
Hi, My issue is i have two different searches, first: index=test user=test document=* second: index=test2 user=test src=home action=view what I would like to do is gather the timestamps from the first search, and add them as a condition for the second search, I would also like to shorten the timestamp to the current hour so I can get the view actions that happen before and after there was a document value. Is there any way of doing this in Splunk?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>