<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Comparing last 2 weeks average against yesterday's events in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370871#M109133</link>
    <description>&lt;P&gt;Hi.. you can try &lt;STRONG&gt;append&lt;/STRONG&gt; OR &lt;STRONG&gt;join&lt;/STRONG&gt; splunk command as per your requirement..&lt;/P&gt;

&lt;P&gt;refer below link&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Append"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Append&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/SearchReference/Join"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.0/SearchReference/Join&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2017 09:23:15 GMT</pubDate>
    <dc:creator>anjambha</dc:creator>
    <dc:date>2017-11-15T09:23:15Z</dc:date>
    <item>
      <title>Comparing last 2 weeks average against yesterday's events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370870#M109132</link>
      <description>&lt;P&gt;I am trying to get last 2 weeks data and avg over week day's  and compare that against event count of yesterday to detect any issue.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=xxxxx  host="xxxxx" earliest=-2w@w latest=@w date_wday!=saturday date_wday!=sunday| bin span=1d _time | eval marker=if (_time&amp;lt;relative_time(now(),"-w@w"), "LastWeek_Weekdays","ThisWeek_Weekdays") | eval _time=if(marker=="LastWeek_Weekdays", _time + 7*24*60*60, _time) | rex "Current Partition:(?&amp;lt;PartitionNumber&amp;gt;\d+),Offset:(?&amp;lt;Offset&amp;gt;\d+),triggerID:(?&amp;lt;TriggerId&amp;gt;\S+),Outputsystem:\d+,IsprodTrigger:\S+,triggerTimeStamp:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartTime:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartDelay:(?&amp;lt;DelayLag&amp;gt;\d+),batchCount:(?&amp;lt;batchCount&amp;gt;\d+),timeGT:(?&amp;lt;createtime&amp;gt;\d+-\d+-\d+\W+\d+:\d+:\d+.\d+)" |dedup PartitionNumber , Offset ,TriggerId   |  chart count  by TriggerId limit=0 marker |  eval  LastWeek_Weekdays_Avg=round(LastWeek_Weekdays/5,0) | append [ search host="xxxx" earliest=-1d@d latest=@d | bin span=1d _time  | eval marker=if (_time&amp;lt;relative_time(now(),"-1d@d"), "Yesterday","Today") | rex "Current Partition:(?&amp;lt;PartitionNumber&amp;gt;\d+),Offset:(?&amp;lt;Offset&amp;gt;\d+),triggerID:(?&amp;lt;TriggerId&amp;gt;\S+),Outputsystem:\d+,IsprodTrigger:\S+,triggerTimeStamp:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartTime:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartDelay:(?&amp;lt;DelayLag&amp;gt;\d+),batchCount:(?&amp;lt;batchCount&amp;gt;\d+),timeGT:(?&amp;lt;createtime&amp;gt;\d+-\d+-\d+\W+\d+:\d+:\d+.\d+)" |dedup PartitionNumber , Offset ,TriggerId |  chart count  by TriggerId, marker  ] | eval diff_In_Percentage=((Yesterday-LastWeek_Weekdays_Avg)/LastWeek_Weekdays_Avg)*100
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And O/p should look like&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    TriggerId   LastWeek_Weekdays   LastWeek_Weekdays_Avg   ThisWeek_Weekdays Yesterday diff_inPercentage
xyz 32301   6460    26118 xx xx%
abc 2146    429 1876 xx xx%
abc123  4   1   5 xx xx%
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 15 Nov 2017 08:07:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370870#M109132</guid>
      <dc:creator>dpatiladobe</dc:creator>
      <dc:date>2017-11-15T08:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Comparing last 2 weeks average against yesterday's events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370871#M109133</link>
      <description>&lt;P&gt;Hi.. you can try &lt;STRONG&gt;append&lt;/STRONG&gt; OR &lt;STRONG&gt;join&lt;/STRONG&gt; splunk command as per your requirement..&lt;/P&gt;

&lt;P&gt;refer below link&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Append"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Append&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/SearchReference/Join"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.0/SearchReference/Join&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 09:23:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370871#M109133</guid>
      <dc:creator>anjambha</dc:creator>
      <dc:date>2017-11-15T09:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Comparing last 2 weeks average against yesterday's events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370872#M109134</link>
      <description>&lt;P&gt;I have updated the question.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 17:27:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370872#M109134</guid>
      <dc:creator>dpatiladobe</dc:creator>
      <dc:date>2017-11-15T17:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: Comparing last 2 weeks average against yesterday's events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370873#M109135</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=xxxxx  host="xxxxx" earliest=-2w@w latest=@w date_wday!=saturday date_wday!=sunday| bin span=1d _time | rex "Current Partition:(?&amp;lt;PartitionNumber&amp;gt;\d+),Offset:(?&amp;lt;Offset&amp;gt;\d+),triggerID:(?&amp;lt;TriggerId&amp;gt;\S+),Outputsystem:\d+,IsprodTrigger:\S+,triggerTimeStamp:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartTime:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartDelay:(?&amp;lt;DelayLag&amp;gt;\d+),batchCount:(?&amp;lt;batchCount&amp;gt;\d+),timeGT:(?&amp;lt;createtime&amp;gt;\d+-\d+-\d+\W+\d+:\d+:\d+.\d+)" |dedup PartitionNumber , Offset ,TriggerId   | stats count by TriggerId _time |  stats avg(count) as count LastWeek_Weekdays_Avg by TriggerId |  eval  LastWeek_Weekdays_Avg=round(LastWeek_Weekdays/5,0) | append [ search host="xxxx" earliest=-1d@d latest=@d | bin span=1d _time  | rex "Current Partition:(?&amp;lt;PartitionNumber&amp;gt;\d+),Offset:(?&amp;lt;Offset&amp;gt;\d+),triggerID:(?&amp;lt;TriggerId&amp;gt;\S+),Outputsystem:\d+,IsprodTrigger:\S+,triggerTimeStamp:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartTime:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartDelay:(?&amp;lt;DelayLag&amp;gt;\d+),batchCount:(?&amp;lt;batchCount&amp;gt;\d+),timeGT:(?&amp;lt;createtime&amp;gt;\d+-\d+-\d+\W+\d+:\d+:\d+.\d+)" |dedup PartitionNumber , Offset ,TriggerId |  stats count as Yesterday by TriggerId ] | stats values(LastWeek_Weekdays_Avg) as LastWeek_Weekdays_Avg values(Yesterday) as Yesterday by TriggerId | eval diff_In_Percentage=((Yesterday-LastWeek_Weekdays_Avg)/LastWeek_Weekdays_Avg)*100
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 15 Nov 2017 18:56:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370873#M109135</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-11-15T18:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: Comparing last 2 weeks average against yesterday's events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370874#M109136</link>
      <description>&lt;P&gt;I was able to get work around with below query but if TriggerId not present in last 2 week and present in yesterday data then it mess up all the calculation&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=xxx  host="xxxx" source="xxx*.log*"  earliest=-2w@w latest=@w date_wday!=saturday date_wday!=sunday| bin span=1d _time | eval marker=if (_time&amp;lt;relative_time(now(),"-w@w"), "Last2Week_Weekdays","LastWeek_Weekdays") | eval _time=if(marker=="Last2Week_Weekdays", _time + 7*24*60*60, _time) | rex "Current Partition:(?&amp;lt;PartitionNumber&amp;gt;\d+),Offset:(?&amp;lt;Offset&amp;gt;\d+),triggerID:(?&amp;lt;TriggerId&amp;gt;\S+),Outputsystem:\d+,IsprodTrigger:\S+,triggerTimeStamp:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartTime:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartDelay:(?&amp;lt;DelayLag&amp;gt;\d+),batchCount:(?&amp;lt;batchCount&amp;gt;\d+),timeGT:(?&amp;lt;createtime&amp;gt;\d+-\d+-\d+\W+\d+:\d+:\d+.\d+)" |dedup PartitionNumber , Offset ,TriggerId   |  chart count  by TriggerId limit=0 marker |  eval  Last2Week_Weekdays_Avg=round(Last2Week_Weekdays/5,0) | eval  LastWeek_Weekdays_Avg=round(LastWeek_Weekdays/5,0)| appendcols [ search host="xxxx" source="xxx*.log*" earliest=-1d@d latest=@d   date_wday!=saturday date_wday!=sunday| bin span=1d _time  | eval marker=if (_time&amp;lt;relative_time(now(),"-0d@d"), "Yesterday","ThisWeek_Weekdays") |eval _time=if(marker=="Yesterday", _time + 1*24*60*60, _time) | rex "Current Partition:(?&amp;lt;PartitionNumber&amp;gt;\d+),Offset:(?&amp;lt;Offset&amp;gt;\d+),triggerID:(?&amp;lt;TriggerId&amp;gt;\S+),Outputsystem:\d+,IsprodTrigger:\S+,triggerTimeStamp:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartTime:\d+-\d+-\d+\W+\d+:\d+:\d+.\d+,StartDelay:(?&amp;lt;DelayLag&amp;gt;\d+),batchCount:(?&amp;lt;batchCount&amp;gt;\d+),timeGT:(?&amp;lt;createtime&amp;gt;\d+-\d+-\d+\W+\d+:\d+:\d+.\d+)" |dedup PartitionNumber , Offset ,TriggerId |  chart count by TriggerId ,marker ] | eval diff_In_Percentage_Week_2=((Yesterday-Last2Week_Weekdays_Avg)/Last2Week_Weekdays_Avg)*100 | eval diff_In_Percentage_Week_Last=((Yesterday-LastWeek_Weekdays_Avg)/LastWeek_Weekdays_Avg)*100
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 15 Nov 2017 22:22:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370874#M109136</guid>
      <dc:creator>dpatiladobe</dc:creator>
      <dc:date>2017-11-15T22:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: Comparing last 2 weeks average against yesterday's events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370875#M109137</link>
      <description>&lt;P&gt;You can assign a default values, say 0 to LastWeek_Weekdays_Avg field if it's null (TriggerId present yesterday but not Last 2 weeks) and vice versa. OR you can just put NA where any one of Yesterday or LastWeek_Weekdays_Avg field is null, so that no calculation will be done.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:48:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370875#M109137</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-09-29T16:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Comparing last 2 weeks average against yesterday's events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370876#M109138</link>
      <description>&lt;P&gt;Thanks . instead of append i used joined and it works perfect.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 04:36:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Comparing-last-2-weeks-average-against-yesterday-s-events/m-p/370876#M109138</guid>
      <dc:creator>dpatiladobe</dc:creator>
      <dc:date>2017-11-16T04:36:03Z</dc:date>
    </item>
  </channel>
</rss>

