Hi,
Is it possible to configure Splunk so that if an error trace occurs, it will start collecting info traces around the error? For example: error trace occurs at 1:00PM. at 1:00 PM Splunk will start to collect info traces since 12:45 PM till 1:15 PM. Errors and info can be saved in distinct files. I am asking because the info traces are too noisy and we would like to collect them according specific needs.
Thanks, Avital