This is not current Splunk documentation.
Splunk 3.4.2 is the latest version. Only use this page with older Splunk 2.0.x.
Splunk 3.4.2 is the latest version. Only use this page with older Splunk 2.0.x.
Splunk User Manual (Splunk v2.0)
Tutorial
Related
Related events have matching rare values between them—not a timestamp, but a rare value such as an IP address, username, or status level. The examples below are two events that have different event types, but you can see that they're related by the IP address.

Splunking for Related events lets you find events that you might not have thought to look for if you needed to specify the shared values explicitly.
No comments have been submitted.