a
b
c
d
e
f
g
h
then, I search "e" and would like to show its 3 neighbor line for both before and after the search text found. I want the search result show like this.
c
d
e
f
g
Could you please advise? Please note that the data doesn't contain the time.
Thank you.
The data itself doesn't contain the time, but Splunk will assign a timestamp to it nevertheless. Anyways, the answer is that unfortunately it can't be EASILY done. It's been discussed in detail here: http://splunk-base.splunk.com/answers/2602/can-splunk-filtermatch-events-and-bring-back-neighbouring...