Knowledge Management

Find the earliest event matching startswith using transaction

nkgon
New Member

So I have a log with multiple VPN connection, and some of them reconnect to the same session multiple times a day for example:

08:02:00- User A login
08:10:12- User A login, replace old connection
08:12:13- User A login, replace old connection
08:15:13- User A logout, disconnected

when I use transaction , splunk only get the events at 08:15:13 and 08:12:13 , but I want it to get the earliest event at 08:02:00, are there any way to achieve that ?

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Ignore the replace old connection events in your startswith condition.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...