Splunk Search

_time from host

jimjohn
Path Finder

I have host A and B.Both of this host have different _time values.Can I use _time from Host A only?
How can i do this?
My purpose is to generate a timechart.

0 Karma

grijhwani
Motivator

The time reference comes from each individual log entry. In order to relate the results for host A and B together, you would need to be performing some kind of joined search where you take results from host A as your principal data source, and then cross-relate to matching results from host B. How you do that depends on what the data is, and what the fixed relationship is between the two machines.

0 Karma

Ayn
Legend

Give more details. Right now it's hard to understand your exact scenario. All events will have a _time value set - what do you mean by just using _time from a certain host? How will that be used for other events?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...