<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk non uniform event sampling in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-non-uniform-event-sampling/m-p/456691#M170507</link>
    <description>&lt;P&gt;Hi @sssignals,&lt;/P&gt;

&lt;P&gt;By default sampling applies to all the data you're calling in with your search. You can work around this by appending results to a search. &lt;/P&gt;

&lt;P&gt;For example in you case, you can call your data for the last 24 hours then append from -7d@d to -2d@d and apply the &lt;CODE&gt;sample&lt;/CODE&gt; command on that &lt;CODE&gt;subsearch&lt;/CODE&gt;which is found here : &lt;A href="https://docs.splunk.com/Documentation/MLApp/4.3.0/User/Customsearchcommands#sample"&gt;https://docs.splunk.com/Documentation/MLApp/4.3.0/User/Customsearchcommands#sample&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This will give you a mix of sampled and non-sampled results. There is one caveat though, you won't be able to run any stats on those results as averages/max/min/etc of sampled data don't really make sense. So it all really depends on what you're trying to achieve. If it's just mixing sampled and non-sampled then it'll work.&lt;/P&gt;

&lt;P&gt;Let me know if that helps.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2019 09:02:20 GMT</pubDate>
    <dc:creator>DavidHourani</dc:creator>
    <dc:date>2019-07-05T09:02:20Z</dc:date>
    <item>
      <title>Splunk non uniform event sampling</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-non-uniform-event-sampling/m-p/456690#M170506</link>
      <description>&lt;P&gt;Hi Splunk community&lt;/P&gt;

&lt;P&gt;I wanted to know if Splunk event sampling can be customized such that there is sampling for events from -7d@d to -2d@d and no sampling for example, last 24 hrs of events.&lt;/P&gt;

&lt;P&gt;I read the documentation so my conclusion is it cannot be done my way. Appreciate the confirmation from the Splunk community.&lt;/P&gt;

&lt;P&gt;I have a lot of events to trend but obviously recent events are more valuable than older events and I really hope to speed up my scheduled reports via non-uniform sampling.&lt;/P&gt;

&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 08:27:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-non-uniform-event-sampling/m-p/456690#M170506</guid>
      <dc:creator>sssignals</dc:creator>
      <dc:date>2019-07-05T08:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk non uniform event sampling</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-non-uniform-event-sampling/m-p/456691#M170507</link>
      <description>&lt;P&gt;Hi @sssignals,&lt;/P&gt;

&lt;P&gt;By default sampling applies to all the data you're calling in with your search. You can work around this by appending results to a search. &lt;/P&gt;

&lt;P&gt;For example in you case, you can call your data for the last 24 hours then append from -7d@d to -2d@d and apply the &lt;CODE&gt;sample&lt;/CODE&gt; command on that &lt;CODE&gt;subsearch&lt;/CODE&gt;which is found here : &lt;A href="https://docs.splunk.com/Documentation/MLApp/4.3.0/User/Customsearchcommands#sample"&gt;https://docs.splunk.com/Documentation/MLApp/4.3.0/User/Customsearchcommands#sample&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This will give you a mix of sampled and non-sampled results. There is one caveat though, you won't be able to run any stats on those results as averages/max/min/etc of sampled data don't really make sense. So it all really depends on what you're trying to achieve. If it's just mixing sampled and non-sampled then it'll work.&lt;/P&gt;

&lt;P&gt;Let me know if that helps.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 09:02:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-non-uniform-event-sampling/m-p/456691#M170507</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-07-05T09:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk non uniform event sampling</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-non-uniform-event-sampling/m-p/456692#M170508</link>
      <description>&lt;P&gt;Thanks DavidHourani. I will try it out and feedback.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2019 15:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-non-uniform-event-sampling/m-p/456692#M170508</guid>
      <dc:creator>sssignals</dc:creator>
      <dc:date>2019-07-15T15:30:27Z</dc:date>
    </item>
  </channel>
</rss>

