<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how can I get an aggregation like max() for multiple happenings over a diffenrent periods? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-can-I-get-an-aggregation-like-max-for-multiple-happenings/m-p/370198#M162095</link>
    <description>&lt;P&gt;My results are in the following table:&lt;BR /&gt;
happening   time_duration       Aufnahme        zaehler_anzahl&lt;BR /&gt;&lt;BR /&gt;
1                   50.405                         Tasche4              685&lt;BR /&gt;
2   48.414  Tasche3     629&lt;BR /&gt;
3   63.486  Tasche2     700&lt;BR /&gt;
4   50.392  Tasche1     618&lt;BR /&gt;
5   49.405  Tasche5     689&lt;BR /&gt;
6   49.348  Tasche4     614&lt;BR /&gt;
7   52.479  Tasche3     694&lt;BR /&gt;
8   49.379  Tasche2     647&lt;BR /&gt;
9   51.425  Tasche1     687&lt;BR /&gt;
10  50.437  Tasche5     638&lt;BR /&gt;
11  51.516  Tasche4     675&lt;BR /&gt;
12  62.422  Tasche3     681&lt;BR /&gt;
13  54.421  Tasche2     682 &lt;BR /&gt;
Now I have the problem to get key-values for every happening followed by an amount of zaehler_anzahl. The curve in this period you will see in the following Picture.&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/229798-unbenannt.gif" alt="alt text" /&gt;&lt;BR /&gt;
At the end I want to habe all these  periods separate to do further analyses.&lt;BR /&gt;
Thanks in advance for your help.&lt;BR /&gt;
George&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 18:36:53 GMT</pubDate>
    <dc:creator>GDude</dc:creator>
    <dc:date>2020-09-29T18:36:53Z</dc:date>
    <item>
      <title>how can I get an aggregation like max() for multiple happenings over a diffenrent periods?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-can-I-get-an-aggregation-like-max-for-multiple-happenings/m-p/370198#M162095</link>
      <description>&lt;P&gt;My results are in the following table:&lt;BR /&gt;
happening   time_duration       Aufnahme        zaehler_anzahl&lt;BR /&gt;&lt;BR /&gt;
1                   50.405                         Tasche4              685&lt;BR /&gt;
2   48.414  Tasche3     629&lt;BR /&gt;
3   63.486  Tasche2     700&lt;BR /&gt;
4   50.392  Tasche1     618&lt;BR /&gt;
5   49.405  Tasche5     689&lt;BR /&gt;
6   49.348  Tasche4     614&lt;BR /&gt;
7   52.479  Tasche3     694&lt;BR /&gt;
8   49.379  Tasche2     647&lt;BR /&gt;
9   51.425  Tasche1     687&lt;BR /&gt;
10  50.437  Tasche5     638&lt;BR /&gt;
11  51.516  Tasche4     675&lt;BR /&gt;
12  62.422  Tasche3     681&lt;BR /&gt;
13  54.421  Tasche2     682 &lt;BR /&gt;
Now I have the problem to get key-values for every happening followed by an amount of zaehler_anzahl. The curve in this period you will see in the following Picture.&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/229798-unbenannt.gif" alt="alt text" /&gt;&lt;BR /&gt;
At the end I want to habe all these  periods separate to do further analyses.&lt;BR /&gt;
Thanks in advance for your help.&lt;BR /&gt;
George&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:36:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-can-I-get-an-aggregation-like-max-for-multiple-happenings/m-p/370198#M162095</guid>
      <dc:creator>GDude</dc:creator>
      <dc:date>2020-09-29T18:36:53Z</dc:date>
    </item>
  </channel>
</rss>

