<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help in complex Search Query alert in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-in-complex-Search-Query-alert/m-p/553709#M5938</link>
    <description>&lt;P&gt;The &lt;STRONG&gt;context&lt;/STRONG&gt; is Splunk is collecting data from a radar device.&lt;/P&gt;&lt;P&gt;Basically what it gets is the &lt;STRONG&gt;Latitude&lt;/STRONG&gt;, &lt;STRONG&gt;Longitude &lt;/STRONG&gt;and&lt;STRONG&gt; Id&lt;/STRONG&gt; of nearby objects in a &lt;EM&gt;x&amp;nbsp;&lt;/EM&gt; meters radius range.&lt;/P&gt;&lt;P&gt;The events are in &lt;STRONG&gt;JSON &lt;/STRONG&gt;format and the following is an exemple:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{
  "Id": 1,
  "Latitude": x,
  "Longitude": y
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk must &lt;STRONG&gt;trigger an alert &lt;/STRONG&gt;when an object which previously was at position &lt;EM&gt;y&lt;/EM&gt;, now is at position &lt;EM&gt;z&lt;/EM&gt; iff delta &lt;EM&gt;z&lt;/EM&gt;-&lt;EM&gt;y&lt;/EM&gt; is too big.&lt;/P&gt;&lt;P&gt;I know the alert can be triggered if the search result returns at least 1 row, but I don't know &lt;STRONG&gt;how to write this query&lt;/STRONG&gt; because too &lt;STRONG&gt;complex&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Is it possibile to make this query? How can I do this?&lt;BR /&gt;Thank you in advance!&lt;/P&gt;</description>
    <pubDate>Mon, 31 May 2021 12:51:05 GMT</pubDate>
    <dc:creator>Unige2021</dc:creator>
    <dc:date>2021-05-31T12:51:05Z</dc:date>
    <item>
      <title>Help in complex Search Query alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-in-complex-Search-Query-alert/m-p/553709#M5938</link>
      <description>&lt;P&gt;The &lt;STRONG&gt;context&lt;/STRONG&gt; is Splunk is collecting data from a radar device.&lt;/P&gt;&lt;P&gt;Basically what it gets is the &lt;STRONG&gt;Latitude&lt;/STRONG&gt;, &lt;STRONG&gt;Longitude &lt;/STRONG&gt;and&lt;STRONG&gt; Id&lt;/STRONG&gt; of nearby objects in a &lt;EM&gt;x&amp;nbsp;&lt;/EM&gt; meters radius range.&lt;/P&gt;&lt;P&gt;The events are in &lt;STRONG&gt;JSON &lt;/STRONG&gt;format and the following is an exemple:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{
  "Id": 1,
  "Latitude": x,
  "Longitude": y
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk must &lt;STRONG&gt;trigger an alert &lt;/STRONG&gt;when an object which previously was at position &lt;EM&gt;y&lt;/EM&gt;, now is at position &lt;EM&gt;z&lt;/EM&gt; iff delta &lt;EM&gt;z&lt;/EM&gt;-&lt;EM&gt;y&lt;/EM&gt; is too big.&lt;/P&gt;&lt;P&gt;I know the alert can be triggered if the search result returns at least 1 row, but I don't know &lt;STRONG&gt;how to write this query&lt;/STRONG&gt; because too &lt;STRONG&gt;complex&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Is it possibile to make this query? How can I do this?&lt;BR /&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 12:51:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-in-complex-Search-Query-alert/m-p/553709#M5938</guid>
      <dc:creator>Unige2021</dc:creator>
      <dc:date>2021-05-31T12:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Help in complex Search Query alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-in-complex-Search-Query-alert/m-p/553718#M5939</link>
      <description>&lt;P&gt;The JSON object only has 3 elements - of two events for the same id, how&amp;nbsp; do you determine which was the previous. Given two events for the same id, how do you determine the diff between two events especially since these look like locations on a sphere?&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 14:53:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-in-complex-Search-Query-alert/m-p/553718#M5939</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-31T14:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Help in complex Search Query alert</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-in-complex-Search-Query-alert/m-p/553730#M5942</link>
      <description>&lt;P&gt;Sorry you are right, I forgot to specify the JSON includes the timestamp too.&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 15:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-in-complex-Search-Query-alert/m-p/553730#M5942</guid>
      <dc:creator>Unige2021</dc:creator>
      <dc:date>2021-05-31T15:58:11Z</dc:date>
    </item>
  </channel>
</rss>

