<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Compare two Splunk Alert search with same time span in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Compare-two-Splunk-Alert-search-with-same-time-span/m-p/576131#M13270</link>
    <description>&lt;P&gt;Dear Professor,&lt;/P&gt;&lt;P&gt;I have two alert search like this&lt;/P&gt;&lt;P&gt;1. Search 1:&lt;/P&gt;&lt;P&gt;index="abc" sourcetype="abc" service.name=financing request.method="POST" request.uri="*/applications" response.status="200"&lt;BR /&gt;|timechart span=2m count as applicaton_today&lt;BR /&gt;|eval mytime=strftime(_time,"%Y-%m-%dT%H:%M")&lt;BR /&gt;|eval yesterday_time=strftime(_time,"%H:%M")&lt;BR /&gt;|fields _time,yesterday_time,applicaton_today&lt;/P&gt;&lt;P&gt;And here is output&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16983i5D81650CDCE3EA4E/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;2. Search 2:&lt;/P&gt;&lt;P&gt;index="xyz" sourcetype="xyz" "Application * sent to xyz success"&lt;BR /&gt;|timechart span=2m count as omni_today&lt;BR /&gt;|eval mytime=strftime(_time,"%Y-%m-%dT%H:%M")&lt;BR /&gt;|eval yesterday_time=strftime(_time,"%H:%M")&lt;BR /&gt;|fields _time,yesterday_time,omni_today&lt;/P&gt;&lt;P&gt;And here is output&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16984iD20126A3FB83E172/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;3. I try to combine two search like this then calculate spike.&lt;/P&gt;&lt;P&gt;index="abc" sourcetype="abc" service.name=financing request.method="POST" request.uri="*/applications" response.status="200"&lt;BR /&gt;|timechart span=2m count as app_today&lt;BR /&gt;|eval mytime=strftime(_time,"%Y-%m-%dT%H:%M")&lt;BR /&gt;|eval yesterday_time=strftime(_time,"%H:%M")&lt;BR /&gt;| append [search index="xyz" sourcetype="xyz" "Application * sent to xyz"&lt;BR /&gt;| timechart span=2m count as omni_today]&lt;BR /&gt;|fields _time,yesterday_time,app_today,omni_today&lt;BR /&gt;|eval spike=if(omni_today &amp;lt; app_today AND _time &amp;lt;= now() - 3*60 AND _time &amp;gt;= relative_time(now(),"@d") + 7.5*3600, 1, 0)&lt;/P&gt;&lt;P&gt;Here is output&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="3.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16987i23FE3F33D5AA9E6A/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;But it shows two time span (like image).&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I combine two search with only time span like this.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="4.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16989i8B23904904D4CB73/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.PNG" alt="4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Nov 2021 07:13:05 GMT</pubDate>
    <dc:creator>lamnguyentt1</dc:creator>
    <dc:date>2021-11-24T07:13:05Z</dc:date>
    <item>
      <title>Compare two Splunk Alert search with same time span</title>
      <link>https://community.splunk.com/t5/Alerting/Compare-two-Splunk-Alert-search-with-same-time-span/m-p/576131#M13270</link>
      <description>&lt;P&gt;Dear Professor,&lt;/P&gt;&lt;P&gt;I have two alert search like this&lt;/P&gt;&lt;P&gt;1. Search 1:&lt;/P&gt;&lt;P&gt;index="abc" sourcetype="abc" service.name=financing request.method="POST" request.uri="*/applications" response.status="200"&lt;BR /&gt;|timechart span=2m count as applicaton_today&lt;BR /&gt;|eval mytime=strftime(_time,"%Y-%m-%dT%H:%M")&lt;BR /&gt;|eval yesterday_time=strftime(_time,"%H:%M")&lt;BR /&gt;|fields _time,yesterday_time,applicaton_today&lt;/P&gt;&lt;P&gt;And here is output&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16983i5D81650CDCE3EA4E/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;2. Search 2:&lt;/P&gt;&lt;P&gt;index="xyz" sourcetype="xyz" "Application * sent to xyz success"&lt;BR /&gt;|timechart span=2m count as omni_today&lt;BR /&gt;|eval mytime=strftime(_time,"%Y-%m-%dT%H:%M")&lt;BR /&gt;|eval yesterday_time=strftime(_time,"%H:%M")&lt;BR /&gt;|fields _time,yesterday_time,omni_today&lt;/P&gt;&lt;P&gt;And here is output&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16984iD20126A3FB83E172/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;3. I try to combine two search like this then calculate spike.&lt;/P&gt;&lt;P&gt;index="abc" sourcetype="abc" service.name=financing request.method="POST" request.uri="*/applications" response.status="200"&lt;BR /&gt;|timechart span=2m count as app_today&lt;BR /&gt;|eval mytime=strftime(_time,"%Y-%m-%dT%H:%M")&lt;BR /&gt;|eval yesterday_time=strftime(_time,"%H:%M")&lt;BR /&gt;| append [search index="xyz" sourcetype="xyz" "Application * sent to xyz"&lt;BR /&gt;| timechart span=2m count as omni_today]&lt;BR /&gt;|fields _time,yesterday_time,app_today,omni_today&lt;BR /&gt;|eval spike=if(omni_today &amp;lt; app_today AND _time &amp;lt;= now() - 3*60 AND _time &amp;gt;= relative_time(now(),"@d") + 7.5*3600, 1, 0)&lt;/P&gt;&lt;P&gt;Here is output&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="3.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16987i23FE3F33D5AA9E6A/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;But it shows two time span (like image).&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I combine two search with only time span like this.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="4.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16989i8B23904904D4CB73/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.PNG" alt="4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 07:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Compare-two-Splunk-Alert-search-with-same-time-span/m-p/576131#M13270</guid>
      <dc:creator>lamnguyentt1</dc:creator>
      <dc:date>2021-11-24T07:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Compare two Splunk Alert search with same time span</title>
      <link>https://community.splunk.com/t5/Alerting/Compare-two-Splunk-Alert-search-with-same-time-span/m-p/576141#M13271</link>
      <description>&lt;P&gt;Well. You simply asked splunk to append results of one search to results of another search. So splunk did it - took rows of results from one search and "glued" them to the end of another search.&lt;/P&gt;&lt;P&gt;You could further transform combined results but it's better to start off without the append in the first place. (subsearches have their own limits and can trigger some tricky behaviour).&lt;/P&gt;&lt;P&gt;Since you're doing mostly same thing with two sets of result data, you can just get all your events amd then calculate separate stats for both kinds of events.&lt;/P&gt;&lt;PRE&gt;(index="abc" sourcetype="abc" service.name=financing request.method="POST" request.uri="*/applications" response.status="200") OR ( index="xyz" sourcetype="xyz" "Application * sent to xyz")&lt;BR /&gt;|timechart span=2m count(eval(sourcetype="abc")) as app_today count(eval(sourcetype="xyz")) as omni_today&lt;BR /&gt;|eval mytime=strftime(_time,"%Y-%m-%dT%H:%M")&lt;BR /&gt;|eval yesterday_time=strftime(_time,"%H:%M")&lt;BR /&gt;|fields _time,yesterday_time,app_today,omni_today&lt;BR /&gt;|eval spike=if(omni_today &amp;lt; app_today AND _time &amp;lt;= now() - 3*60 AND _time &amp;gt;= relative_time(now(),"@d") + 7.5*3600, 1, 0)&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 08:21:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Compare-two-Splunk-Alert-search-with-same-time-span/m-p/576141#M13271</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-24T08:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Compare two Splunk Alert search with same time span</title>
      <link>https://community.splunk.com/t5/Alerting/Compare-two-Splunk-Alert-search-with-same-time-span/m-p/576146#M13272</link>
      <description>&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;P&gt;With my way, it's really easy by change "append" to "appendcols".&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 08:31:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Compare-two-Splunk-Alert-search-with-same-time-span/m-p/576146#M13272</guid>
      <dc:creator>lamnguyentt1</dc:creator>
      <dc:date>2021-11-24T08:31:08Z</dc:date>
    </item>
  </channel>
</rss>

