<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Display result when comparing 3 fields, only show greater by 100 for one field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Display-result-when-comparing-3-fields-only-show-greater-by-100/m-p/511633#M143440</link>
    <description>&lt;P&gt;I have a search that is giving me this data set:&lt;/P&gt;&lt;P&gt;ID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;status&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Stamp&lt;BR /&gt;alex&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;esb&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1595989827764&lt;BR /&gt;alex&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;fuz&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1595989827762&lt;BR /&gt;jake&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;esb&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1596056447122&lt;BR /&gt;jake&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;fuz&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1596056447085&lt;BR /&gt;josh&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;esb&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1596054751935&lt;BR /&gt;josh&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;fuz&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1596054751852&lt;BR /&gt;stefan&amp;nbsp; &amp;nbsp; esb&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1596056406846&lt;BR /&gt;stefan&amp;nbsp; &amp;nbsp; fuz&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1596056406806&lt;/P&gt;&lt;P&gt;I want to compare the Stamp by ID, and show any ID's where the stamp for esb is great than the stampe for fuz by at least 100. Any help appreciated.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jul 2020 21:21:06 GMT</pubDate>
    <dc:creator>baustin612</dc:creator>
    <dc:date>2020-07-29T21:21:06Z</dc:date>
    <item>
      <title>Display result when comparing 3 fields, only show greater by 100 for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-result-when-comparing-3-fields-only-show-greater-by-100/m-p/511633#M143440</link>
      <description>&lt;P&gt;I have a search that is giving me this data set:&lt;/P&gt;&lt;P&gt;ID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;status&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Stamp&lt;BR /&gt;alex&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;esb&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1595989827764&lt;BR /&gt;alex&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;fuz&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1595989827762&lt;BR /&gt;jake&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;esb&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1596056447122&lt;BR /&gt;jake&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;fuz&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1596056447085&lt;BR /&gt;josh&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;esb&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1596054751935&lt;BR /&gt;josh&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;fuz&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1596054751852&lt;BR /&gt;stefan&amp;nbsp; &amp;nbsp; esb&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1596056406846&lt;BR /&gt;stefan&amp;nbsp; &amp;nbsp; fuz&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1596056406806&lt;/P&gt;&lt;P&gt;I want to compare the Stamp by ID, and show any ID's where the stamp for esb is great than the stampe for fuz by at least 100. Any help appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 21:21:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-result-when-comparing-3-fields-only-show-greater-by-100/m-p/511633#M143440</guid>
      <dc:creator>baustin612</dc:creator>
      <dc:date>2020-07-29T21:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: Display result when comparing 3 fields, only show greater by 100 for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-result-when-comparing-3-fields-only-show-greater-by-100/m-p/511636#M143442</link>
      <description>&lt;P&gt;|stats range(Stamp) as duration by ID&lt;/P&gt;&lt;P&gt;|where duration &amp;gt; 100&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 21:38:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-result-when-comparing-3-fields-only-show-greater-by-100/m-p/511636#M143442</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-29T21:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Display result when comparing 3 fields, only show greater by 100 for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-result-when-comparing-3-fields-only-show-greater-by-100/m-p/511639#M143444</link>
      <description>&lt;P&gt;Thank you for the quick reply!&lt;/P&gt;&lt;P&gt;How does this take into account status? I only want to display those where 'esb' timestamp is &amp;gt;= 'fuz' timestamp +100.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 21:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-result-when-comparing-3-fields-only-show-greater-by-100/m-p/511639#M143444</guid>
      <dc:creator>baustin612</dc:creator>
      <dc:date>2020-07-29T21:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Display result when comparing 3 fields, only show greater by 100 for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-result-when-comparing-3-fields-only-show-greater-by-100/m-p/511650#M143451</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Your Stamps haven't any greater than 100 so I use greater than 50.&lt;/P&gt;&lt;LI-CODE lang="java"&gt;index=_internal | head 1
| eval _raw="ID,             status,       Stamp
alex,esb,1595989827764
alex,fuz,1595989827762
jake,esb,1596056447122
jake,fuz,1596056447085
josh,fuz,1596054751852
josh,esb,1596054751935
stefan,esb,1596056406846
stefan,fuz,1596056406806" 
| multikv forceheader=1
| eval stamp=tonumber(trim(stamp))
| rename COMMENT as "previous prepare sample data"
| eval esb_stamp = if(status == "esb", Stamp, null())
| eventstats range(Stamp) as duration values(esb_stamp) as esb_stamp by ID
| table duration ID status Stamp esb_stamp
| where esb_stamp &amp;gt;= 50 + Stamp&lt;/LI-CODE&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 22:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-result-when-comparing-3-fields-only-show-greater-by-100/m-p/511650#M143451</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-29T22:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Display result when comparing 3 fields, only show greater by 100 for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Display-result-when-comparing-3-fields-only-show-greater-by-100/m-p/512880#M143870</link>
      <description>&lt;P&gt;Thank you very much!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 20:17:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Display-result-when-comparing-3-fields-only-show-greater-by-100/m-p/512880#M143870</guid>
      <dc:creator>baustin612</dc:creator>
      <dc:date>2020-08-06T20:17:13Z</dc:date>
    </item>
  </channel>
</rss>

