<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Compare current events with events in csv in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487711#M83503</link>
    <description>&lt;P&gt;I don't understand your description of the CSV.  Can you put it in table form?&lt;/P&gt;</description>
    <pubDate>Wed, 29 Apr 2020 13:04:05 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-04-29T13:04:05Z</dc:date>
    <item>
      <title>Compare current events with events in csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487706#M83498</link>
      <description>&lt;P&gt;I have a csv file which has fields say&lt;BR /&gt;
_time success_count failed_count. Every 5 min we have data in these fields. This data is for past say 4 months. Now what I need is to compare current data every 5 min by the data in csv to calculate week over week. Like say success_count today to be compared with the count one and two weeks back same time present in csv and calculate difference in them.&lt;BR /&gt;&lt;BR /&gt;
I have data in csv from December- February and now want to compare my current data( april data) with dec or jan or feb same time just a week before todays date in month say jan.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:14:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487706#M83498</guid>
      <dc:creator>ksharma7</dc:creator>
      <dc:date>2020-09-30T05:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Compare current events with events in csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487707#M83499</link>
      <description>&lt;P&gt;Is the CSV file indexed?  It would be much easier to do what you want with indexed data.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 17:32:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487707#M83499</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-04-27T17:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Compare current events with events in csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487708#M83500</link>
      <description>&lt;P&gt;Well I have a.csv which has columns &lt;BR /&gt;
_time ( having date and time) site1 sitepart2 success_count failure_count.&lt;BR /&gt;
For say site1 I have values say x y z and for x i have sitepart2 as d f g and for y also d f g. I have one lookup b.csv which has all site1 in it.&lt;BR /&gt;
 What I want is to create an alert which will show me output say,&lt;BR /&gt;
Site1 sitepart2 week1 week2 currentsuccess change&lt;BR /&gt;
And trigger alert upon some condition say change&amp;gt;80 and week1 week2 success count should be picked from a.csv&lt;/P&gt;

&lt;P&gt;For indexing csv , how can I do that in this case?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:14:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487708#M83500</guid>
      <dc:creator>ksharma7</dc:creator>
      <dc:date>2020-09-30T05:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Compare current events with events in csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487709#M83501</link>
      <description>&lt;P&gt;I probably cannot index my csv because of permissions issues but will check. If you can help with indexed and non indexed query that would be helpful&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 17:58:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487709#M83501</guid>
      <dc:creator>ksharma7</dc:creator>
      <dc:date>2020-04-27T17:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Compare current events with events in csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487710#M83502</link>
      <description>&lt;P&gt;Also I'm working on splunk enterprise&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 07:04:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487710#M83502</guid>
      <dc:creator>ksharma7</dc:creator>
      <dc:date>2020-04-28T07:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Compare current events with events in csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487711#M83503</link>
      <description>&lt;P&gt;I don't understand your description of the CSV.  Can you put it in table form?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 13:04:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487711#M83503</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-04-29T13:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Compare current events with events in csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487712#M83504</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; , Let me frame question again:&lt;BR /&gt;
Below is a query which I use to get week over week comparison and get alerted:&lt;BR /&gt;
index=rxc_connect event="Go" success=true host=rxc* sourcetype=abc  earliest=-2w-30m@m latest=-2w@m tid=50  [|inputlookup quest.csv | fields tid source ] | fillnull value=0 | stats count as f2 by tid,source, prod| append [search index=rxc_connect event="Go" success=true host=rxc* sourcetype=abc earliest=-1w-30m@m latest=-1w@m tid=50  [|inputlookup quest.csv | fields tid source ] | fillnull value=0 | stats count as f1 by tid,source, prod] | append [search index=rxc_connect event="Go" success=true host=rxc* sourcetype=abc earliest=-30m@m latest=@m  tid=50  [|inputlookup quest.csv | fields tid site ] | fillnull value=0 | stats count as f by tid,source, prod ] | fillnull value=0 | stats max(f1) as Week1,max(f2) as Week2, max(f) as Current by tid, source,prod | eval Average_2W = round(((Week1+Week2)/2),0) | where (Current&amp;lt; Average_2W) |eval change = round((((Average_2W - Current)/Average_2W)*100),0) | where (Average_2W &amp;gt; 30 AND change &amp;gt;=50) &lt;/P&gt;

&lt;P&gt;Now I do not have data for last two weeks to compare with current in splunk but I have saved data in form of csv like below from month of Dec to Feb. Now I want that say today is 02/05/2020 01:00 till 02/05/2020 01:30 should be compared with same date same time same day of any other month for week over week calculation:&lt;/P&gt;

&lt;P&gt;CSV I have is like xyz.csv:&lt;BR /&gt;
_time                                    ID           source prod Success failed&lt;BR /&gt;
01/12/2019 00:00:00.        1             a           q           1.          0&lt;BR /&gt;
01/12/2019 00:00:00          2            b.           r           2            1&lt;BR /&gt;
01/12/2019 00:05:00.         1            a            q           3            0&lt;/P&gt;

&lt;P&gt;Csv quest has combinations of ID source prod available with ID being unique and can have multiple prod associated to it&lt;BR /&gt;
Id tid source prod&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:11:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487712#M83504</guid>
      <dc:creator>ksharma7</dc:creator>
      <dc:date>2020-09-30T05:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: Compare current events with events in csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487713#M83505</link>
      <description>&lt;P&gt;And also is there any other advance way which can help me with comparison without may be using this dumped csv data. May be some advance query which can help me find any dips in my data without even using two three months back data&lt;/P&gt;</description>
      <pubDate>Sat, 02 May 2020 11:47:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487713#M83505</guid>
      <dc:creator>ksharma7</dc:creator>
      <dc:date>2020-05-02T11:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: Compare current events with events in csv</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487714#M83506</link>
      <description>&lt;P&gt;You can try something like this:&lt;/P&gt;

&lt;P&gt;|inputlookup yourlookup_name.csv | &lt;CODE&gt;hoursago(24)&lt;/CODE&gt; | fields + field1, field2, success_count | appendcols [|inputlookup yourlookup_name.csv | &lt;CODE&gt;hoursago(336)&lt;/CODE&gt; | rename success_count as success_count1 | table field1, field2, success_count1] | eval difference=success_count1 - success_count | table difference&lt;/P&gt;

&lt;P&gt;This search will pull your new values upto 24 hours. Then will pull values from 2 weeks back. Eval command will take care of subtraction, which you can play with as per your needs.&lt;/P&gt;

&lt;P&gt;Let me know if it helps!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:17:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Compare-current-events-with-events-in-csv/m-p/487714#M83506</guid>
      <dc:creator>shivanshu1593</dc:creator>
      <dc:date>2020-09-30T05:17:25Z</dc:date>
    </item>
  </channel>
</rss>

