<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can someone file a bug report for me in #Random</title>
    <link>https://community.splunk.com/t5/Random/Can-someone-file-a-bug-report-for-me/m-p/434046#M552</link>
    <description>&lt;P&gt;@mattlucas719 this is not a bug, this is an expected behavior of number represented as string. For your use case you should be comparing &lt;CODE&gt;last_log_seconds&amp;gt;3600&lt;/CODE&gt;. &lt;/P&gt;

&lt;P&gt;Try out the following two run anywhere searches.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;1) &lt;CODE&gt;Sorts by numeric data i.e. 1,2,10,20&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|  makeresults
|  eval data="1,10,2,20"
|  makemv data delim=","
|  mvexpand data
|  eval data_string="str".data
|  sort data
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;2) &lt;CODE&gt;Sorts by string data i.e. 1,10,2,20&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|  makeresults
|  eval data="1,10,2,20"
|  makemv data delim=","
|  mvexpand data
|  eval data_string="str".data
|  sort data_string
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;On similar lines as above if you apply&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;filter &lt;CODE&gt;| search data&amp;gt;=2&lt;/CODE&gt;, it will do numeric filter, returning &lt;CODE&gt;2,10,20&lt;/CODE&gt;:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|  makeresults
|  eval data="1,10,2,20"
|  makemv data delim=","
|  mvexpand data
|  search data&amp;gt;=2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;and filter &lt;CODE&gt;| search data&amp;gt;="2"&lt;/CODE&gt;,  will do string filter, returning &lt;CODE&gt;2,20&lt;/CODE&gt;:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|  makeresults
|  eval data="1,10,2,20"
|  makemv data delim=","
|  mvexpand data
|  search data&amp;gt;="2"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this clarifies behavior.&lt;/P&gt;

&lt;P&gt;PS: While it does not matter much with metadata command however, as a performance optimization suggestion, you should apply the filter before stats. Try the following search with metadata:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| metadata type=sourcetypes index=_internal
| stats max(recentTime) as last_heartbeat by sourcetype
| eval "last_log_seconds"= ( now() - last_heartbeat ) 
| search last_log_seconds &amp;gt; 3600
| stats count by sourcetype, last_log_seconds, last_heartbeat
| fields - count
| fieldformat last_heartbeat=strftime(last_heartbeat,"%F %T")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you are maintaining a lookup/kvstore of all hosts, you can refer to &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Addinfo#2._Determine_which_heartbeats_are_later_than_expected"&gt;Splunk Documentation&lt;/A&gt; to do something similar using tstats and addinfo command as well (example uses &lt;CODE&gt;expected_hosts&lt;/CODE&gt;  lookup):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats latest(_time) as latest_time where index=_internal by host 
| addinfo 
| eval latest_age = info_max_time - latest_time 
| fields - info_*
| inputlookup append=t expected_hosts 
| fillnull value=9999 latest_age 
| dedup host 
| where latest_age &amp;gt; 42
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 29 Apr 2019 17:11:18 GMT</pubDate>
    <dc:creator>niketn</dc:creator>
    <dc:date>2019-04-29T17:11:18Z</dc:date>
    <item>
      <title>Can someone file a bug report for me</title>
      <link>https://community.splunk.com/t5/Random/Can-someone-file-a-bug-report-for-me/m-p/434045#M551</link>
      <description>&lt;P&gt;i don't have an active license but i want to file a bug report for this logic string/number issue i noticed in both "search and  where"&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;| metadata type=hosts index=_internal &lt;BR /&gt;
| stats max(recentTime) as latest by host&lt;BR /&gt;
| eval last_heartbeat=strftime(latest,"%F %T") &lt;BR /&gt;
| eval time_now=now() &lt;BR /&gt;
| eval "last_log_seconds"= ( time_now - latest ) &lt;BR /&gt;
| stats count by host last_log_seconds, last_heartbeat &lt;BR /&gt;
| where last_log_seconds &amp;gt; "3600"&lt;BR /&gt;
| fields - count&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;run that in your splunk environment and you'll see that it returns invalid results, but when you remove the quotes around the number it works fine.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;| metadata type=hosts index=_internal &lt;BR /&gt;
| stats max(recentTime) as latest by host&lt;BR /&gt;
| eval last_heartbeat=strftime(latest,"%F %T") &lt;BR /&gt;
| eval time_now=now() &lt;BR /&gt;
| eval "last_log_seconds"= ( time_now - latest ) &lt;BR /&gt;
| stats count by host last_log_seconds, last_heartbeat &lt;BR /&gt;
| where last_log_seconds &amp;gt; 3600&lt;BR /&gt;
| fields - count&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Splunk Cloud&lt;/P&gt;

&lt;P&gt;Splunk Version&lt;BR /&gt;
7.0.8.5&lt;BR /&gt;
Splunk Build&lt;BR /&gt;
c3e02dedf40a&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:18:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Random/Can-someone-file-a-bug-report-for-me/m-p/434045#M551</guid>
      <dc:creator>mattlucas719</dc:creator>
      <dc:date>2020-09-30T00:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone file a bug report for me</title>
      <link>https://community.splunk.com/t5/Random/Can-someone-file-a-bug-report-for-me/m-p/434046#M552</link>
      <description>&lt;P&gt;@mattlucas719 this is not a bug, this is an expected behavior of number represented as string. For your use case you should be comparing &lt;CODE&gt;last_log_seconds&amp;gt;3600&lt;/CODE&gt;. &lt;/P&gt;

&lt;P&gt;Try out the following two run anywhere searches.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;1) &lt;CODE&gt;Sorts by numeric data i.e. 1,2,10,20&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|  makeresults
|  eval data="1,10,2,20"
|  makemv data delim=","
|  mvexpand data
|  eval data_string="str".data
|  sort data
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;2) &lt;CODE&gt;Sorts by string data i.e. 1,10,2,20&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|  makeresults
|  eval data="1,10,2,20"
|  makemv data delim=","
|  mvexpand data
|  eval data_string="str".data
|  sort data_string
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;On similar lines as above if you apply&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;filter &lt;CODE&gt;| search data&amp;gt;=2&lt;/CODE&gt;, it will do numeric filter, returning &lt;CODE&gt;2,10,20&lt;/CODE&gt;:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|  makeresults
|  eval data="1,10,2,20"
|  makemv data delim=","
|  mvexpand data
|  search data&amp;gt;=2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;and filter &lt;CODE&gt;| search data&amp;gt;="2"&lt;/CODE&gt;,  will do string filter, returning &lt;CODE&gt;2,20&lt;/CODE&gt;:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|  makeresults
|  eval data="1,10,2,20"
|  makemv data delim=","
|  mvexpand data
|  search data&amp;gt;="2"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this clarifies behavior.&lt;/P&gt;

&lt;P&gt;PS: While it does not matter much with metadata command however, as a performance optimization suggestion, you should apply the filter before stats. Try the following search with metadata:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| metadata type=sourcetypes index=_internal
| stats max(recentTime) as last_heartbeat by sourcetype
| eval "last_log_seconds"= ( now() - last_heartbeat ) 
| search last_log_seconds &amp;gt; 3600
| stats count by sourcetype, last_log_seconds, last_heartbeat
| fields - count
| fieldformat last_heartbeat=strftime(last_heartbeat,"%F %T")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you are maintaining a lookup/kvstore of all hosts, you can refer to &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Addinfo#2._Determine_which_heartbeats_are_later_than_expected"&gt;Splunk Documentation&lt;/A&gt; to do something similar using tstats and addinfo command as well (example uses &lt;CODE&gt;expected_hosts&lt;/CODE&gt;  lookup):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats latest(_time) as latest_time where index=_internal by host 
| addinfo 
| eval latest_age = info_max_time - latest_time 
| fields - info_*
| inputlookup append=t expected_hosts 
| fillnull value=9999 latest_age 
| dedup host 
| where latest_age &amp;gt; 42
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 29 Apr 2019 17:11:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Random/Can-someone-file-a-bug-report-for-me/m-p/434046#M552</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2019-04-29T17:11:18Z</dc:date>
    </item>
  </channel>
</rss>

