<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to use streamstats to evaluate events from different sourcetypes? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-streamstats-to-evaluate-events-from-different/m-p/504513#M140867</link>
    <description>&lt;P&gt;Background:&amp;nbsp; I'm trying to create a monthly report that tracks how many terminals we Add and how many terminals we Remove at a property.&amp;nbsp; We have two separate events that track these:&amp;nbsp; RoomTerminalAdd and RoomTerminalRemove.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes we have field reps that need to troubleshoot these terminals and end up with multiples of these events that don't actually indicate a full Add or Remove.&amp;nbsp; I would like to "pair up" these events and evaluate the time differences based on the property, room number, and terminal address.&amp;nbsp; If the time difference is below 15 minutes then I want to removed them from the final monthly count.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a visual to help explain what I'm trying to do:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bhavlik_0-1592261741653.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9193iC85E6272E1963CE7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bhavlik_0-1592261741653.png" alt="bhavlik_0-1592261741653.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;After removing these "pairs" that fit the &amp;lt;15 min time difference, I want to then get a total count of each event type separately.&amp;nbsp; &amp;nbsp;TerminalsAdded=##&amp;nbsp; TerminalsRemoved=##&lt;/P&gt;&lt;P&gt;I have used the command transaction in the past but won't work here as it removes any events that don't have a pair and I need to keep those for my overall count.&amp;nbsp; My next option would be streamstats but I don't have any experience with using that command and not sure how to bring in the time difference for evaluating what to keep and what to remove from search.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone out there have any advice or tips on how to reach my end goal?&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jun 2020 23:03:00 GMT</pubDate>
    <dc:creator>bhavlik</dc:creator>
    <dc:date>2020-06-15T23:03:00Z</dc:date>
    <item>
      <title>How to use streamstats to evaluate events from different sourcetypes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-streamstats-to-evaluate-events-from-different/m-p/504513#M140867</link>
      <description>&lt;P&gt;Background:&amp;nbsp; I'm trying to create a monthly report that tracks how many terminals we Add and how many terminals we Remove at a property.&amp;nbsp; We have two separate events that track these:&amp;nbsp; RoomTerminalAdd and RoomTerminalRemove.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes we have field reps that need to troubleshoot these terminals and end up with multiples of these events that don't actually indicate a full Add or Remove.&amp;nbsp; I would like to "pair up" these events and evaluate the time differences based on the property, room number, and terminal address.&amp;nbsp; If the time difference is below 15 minutes then I want to removed them from the final monthly count.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's a visual to help explain what I'm trying to do:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bhavlik_0-1592261741653.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9193iC85E6272E1963CE7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bhavlik_0-1592261741653.png" alt="bhavlik_0-1592261741653.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;After removing these "pairs" that fit the &amp;lt;15 min time difference, I want to then get a total count of each event type separately.&amp;nbsp; &amp;nbsp;TerminalsAdded=##&amp;nbsp; TerminalsRemoved=##&lt;/P&gt;&lt;P&gt;I have used the command transaction in the past but won't work here as it removes any events that don't have a pair and I need to keep those for my overall count.&amp;nbsp; My next option would be streamstats but I don't have any experience with using that command and not sure how to bring in the time difference for evaluating what to keep and what to remove from search.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone out there have any advice or tips on how to reach my end goal?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 23:03:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-streamstats-to-evaluate-events-from-different/m-p/504513#M140867</guid>
      <dc:creator>bhavlik</dc:creator>
      <dc:date>2020-06-15T23:03:00Z</dc:date>
    </item>
  </channel>
</rss>

