<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Calculate percentage increase/decrease of indexing volume compared to average indexing volume in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360853#M65837</link>
    <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*license_usage.log type=Usage earliest=-7d@d latest=now 
| bucket span=1d _time | stats sum(b) as usage by _time idx 
| eval period=if(_time&amp;lt;relative_time(now(),"@d"),"averageMB","averageMBD") 
| chart avg(usage) over idx by period
| eval averageMB=round(averageMB/1024/1024,2) | eval averageMBD=round(averageMBD/1024/1024,2)
| rename idx as series
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 03 May 2017 14:36:22 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2017-05-03T14:36:22Z</dc:date>
    <item>
      <title>Calculate percentage increase/decrease of indexing volume compared to average indexing volume</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360851#M65835</link>
      <description>&lt;P&gt;I want to trigger an alert if there is 50% increase/decrease of today's indexing volume versus average indexing volume of last 7 days.&lt;BR /&gt;
I've written below query but last 7 days have 60 indexes and today's have 57 indexes and by the query I am getting only 57 indexes. I want to write 0 in today's index so that alert would trigger for no data in that index. and able to calculate the percentage change&lt;/P&gt;

&lt;P&gt;index=&lt;EM&gt;internal source=*metrics.log group=per_index_thruput earliest=-7d latest=now NOT (series=&lt;/EM&gt;* OR series=summary) | bucket &lt;EM&gt;time span=1d | stats sum(kb) as total by series,_time | stats avg(total) as average by series | eval averageMB=round(average/1024,2) | table series averageMB | join type=left series [ search index=_internal source=*metrics.log group=per_index_thruput earliest=@d latest=now NOT (series=&lt;/EM&gt;* OR series=summary)| bucket _time span=1h | stats sum(kb) as total1 by series,_time | stats avg(total1) as average1 by series | eval averageMBD=round(average1/1024,2) | table series averageMBD] | table series averageMB averageMBD&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:55:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360851#M65835</guid>
      <dc:creator>isha_rastogi</dc:creator>
      <dc:date>2020-09-29T13:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate percentage increase/decrease of indexing volume compared to average indexing volume</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360852#M65836</link>
      <description>&lt;P&gt;@isha_rastogi please re-post the query with Code button 101010 so that query does not get filtered.&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 13:34:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360852#M65836</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-05-03T13:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate percentage increase/decrease of indexing volume compared to average indexing volume</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360853#M65837</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*license_usage.log type=Usage earliest=-7d@d latest=now 
| bucket span=1d _time | stats sum(b) as usage by _time idx 
| eval period=if(_time&amp;lt;relative_time(now(),"@d"),"averageMB","averageMBD") 
| chart avg(usage) over idx by period
| eval averageMB=round(averageMB/1024/1024,2) | eval averageMBD=round(averageMBD/1024/1024,2)
| rename idx as series
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 03 May 2017 14:36:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360853#M65837</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-05-03T14:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate percentage increase/decrease of indexing volume compared to average indexing volume</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360854#M65838</link>
      <description>&lt;P&gt;Here's one way...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=internal source=*metrics.log group=per_index_thruput earliest=-7d latest=now 
NOT (series= OR series=summary) 
| bucket _time span=1d 
| stats sum(kb) as totalDay by series,_time 
| stats avg(totalDay) as avgTotal by series 
| eval avgTotalMB=round(avgTotal/1024,2) 
| table series avgTotalMB
| rename COMMENT as "Above, we get your weekly averages."

| rename COMMENT as "We use appendpipe so we can grab the series names."
| appendpipe 
  [| rename COMMENT as "First, we create one zero detail record for each hour for each series"
   | eval hours=mvrange(relative_time(now(),"@d"),now(),3600) 
   | mvexpand hours 
   | eval _time=hours 
   | eval kb=0
   | table _time series kb 

   | rename COMMENT as "Next, we add the real detail, but don't sum it yet."
   | append  
     [ search index=internal source=*metrics.log group=per_index_thruput 
       earliest=@d latest=now NOT (series= OR series=summary)
       | bucket _time span=1h] 
   | stats sum(kb) as totalHour by series,_time 
   | stats avg(totalHour) as avgHour by series 
   | eval todaysCalcMBD=round(24*avgHour/1024,2) 
   | table series todaysCalcMBD
   ] 

| rename COMMENT as "Finally, we roll them together."
| stats values(*) as * by series
| table series avgTotalMB todaysCalcMBD
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This is air code, but it should be close.  I've modified the variable names to make it clear what they are, and to avoid problematic terms.  Best practices are to avoid common words and reserved words like "average" as variable names.   &lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 14:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360854#M65838</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-05-03T14:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate percentage increase/decrease of indexing volume compared to average indexing volume</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360855#M65839</link>
      <description>&lt;P&gt;I'd like to see a scaling factor in there for today's usage, something like&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*license_usage.log type=Usage earliest=-7d@d latest=now (idx=ciscoise OR idx=cyberark_logs OR idx=netscaler)
 | bucket span=1d _time 
 | stats sum(b) as usage by _time idx 
 | eval period=if(_time&amp;lt;relative_time(now(),"@d"),"averageMB",mvappend("todayMBActual","todayMBProjected"))
 | mvexpand period  
 | chart avg(usage) over idx by period
 | eval averageMB=round(averageMB/1024/1024,2) 
 | eval todayMBActual=round(todayMBActual/1024/1024,2)
 | eval tempscale=86400 / (now()-relative_time(now(),"@d"))
 | eval todayMBProjected=round(tempscale*todayMBProjected/1024/1024,2)
 | fields - tempscale
 | rename idx as series
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 03 May 2017 16:12:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360855#M65839</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-05-03T16:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate percentage increase/decrease of indexing volume compared to average indexing volume</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360856#M65840</link>
      <description>&lt;P&gt;Can you please explain the query little more, "tempscale ". &lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 05:09:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360856#M65840</guid>
      <dc:creator>isha_rastogi</dc:creator>
      <dc:date>2017-05-04T05:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate percentage increase/decrease of indexing volume compared to average indexing volume</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360857#M65841</link>
      <description>&lt;P&gt;Can I use something like below to get percentage change?&lt;/P&gt;

&lt;P&gt;index=&lt;EM&gt;internal source=*metrics.log group=per_index_thruput earliest=-7d latest=now()&lt;BR /&gt;
 NOT (series=&lt;/EM&gt;* OR series=summary) &lt;BR /&gt;
 | bucket &lt;EM&gt;time span=1d &lt;BR /&gt;
 | stats sum(kb) as totalDay by series,_time &lt;BR /&gt;
 | stats avg(totalDay) as avgTotal by series &lt;BR /&gt;
 | eval avgTotalMB=round(avgTotal/1024,2) &lt;BR /&gt;
 | table series avgTotalMB | join type=outer series&lt;BR /&gt;&lt;BR /&gt;
      [ search index=_internal source=*metrics.log group=per_index_thruput &lt;BR /&gt;
        earliest=@d latest=now NOT (series=&lt;/EM&gt;* OR series=summary)&lt;BR /&gt;
        | bucket _time span=1h | stats sum(kb) as totalHour by series,_time &lt;BR /&gt;
    | stats avg(totalHour) as avgHour by series &lt;BR /&gt;
    | eval todaysCalcMBD=round(24*avgHour/1024,2) &lt;BR /&gt;
    | table series todaysCalcMBD&lt;BR /&gt;
    ]|  eval perc_change = (todaysCalcMBD-avgTotalMB)/avgTotalMB| eval perc = perc_change * 100| table series avgTotalMB todaysCalcMBD perc | fillnull value=0&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:56:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360857#M65841</guid>
      <dc:creator>isha_rastogi</dc:creator>
      <dc:date>2020-09-29T13:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate percentage increase/decrease of indexing volume compared to average indexing volume</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360858#M65842</link>
      <description>&lt;P&gt;101010 instead of internal it's underscore &lt;EM&gt;internal and series!=underscore star series!=&lt;/EM&gt;*&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 08:31:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360858#M65842</guid>
      <dc:creator>isha_rastogi</dc:creator>
      <dc:date>2017-05-05T08:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate percentage increase/decrease of indexing volume compared to average indexing volume</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360859#M65843</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt; - What if I have to consider the average till yesterday. Because if i'll take now it will consider today's data which will give incorrect metrics&lt;BR /&gt;
Can you help me with the earliest and latest of average and today's &lt;BR /&gt;
For one day I am considering earliest=-24h latest=now which will give me indexing volume for last 24 hours and for average(comparison metrics) it should not include that 24 hours. Not able to put earliesr latest for average and one day&lt;BR /&gt;
index=_internal source=*license_usage.log type=Usage earliest=-7d@d latest=-24h&lt;BR /&gt;
 | bucket span=1d _time | stats sum(b) as usage by _time idx &lt;BR /&gt;
 | eval period=if(_time&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:58:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360859#M65843</guid>
      <dc:creator>isha_rastogi</dc:creator>
      <dc:date>2020-09-29T13:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Calculate percentage increase/decrease of indexing volume compared to average indexing volume</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360860#M65844</link>
      <description>&lt;P&gt;@somesoni2 - How can I use relative_time to consider average  only yesterday's data and earliest and latest =-7d@d and latest=-2d@d&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 10:18:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Calculate-percentage-increase-decrease-of-indexing-volume/m-p/360860#M65844</guid>
      <dc:creator>isha_rastogi</dc:creator>
      <dc:date>2017-05-08T10:18:29Z</dc:date>
    </item>
  </channel>
</rss>

