<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field value changes for two environments in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588263#M204867</link>
    <description>&lt;P&gt;That's a good point, the alerts is looking back at the last one hour so it doesn't have anything to compare to. I'll try it with 2 hours. The problem is it takes 2 hours to wait for results&lt;/P&gt;</description>
    <pubDate>Wed, 09 Mar 2022 16:09:37 GMT</pubDate>
    <dc:creator>Fe-atSplunk</dc:creator>
    <dc:date>2022-03-09T16:09:37Z</dc:date>
    <item>
      <title>How to find field value changes for two environments?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588182#M204837</link>
      <description>&lt;P&gt;There are two environments, INT and PROD. The value of IREFFECTIVEDATE in INT is always the same, as is PROD, however they have different values. I want to know when the value of IREFFECTIVEDATE in its environment changes. Here is a log sample:&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#999999"&gt;&lt;SPAN&gt;2022-03-04&lt;/SPAN&gt; 14:13:00.006, &lt;SPAN&gt;IREFFECTIVEDATE=&lt;/SPAN&gt;"&lt;SPAN&gt;2016-07-01&lt;/SPAN&gt; 00:00:00.0", &lt;SPAN&gt;IRLOANRATE=&lt;/SPAN&gt;"&lt;SPAN&gt;5&lt;/SPAN&gt;"&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;So far my search is this:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index= xy sourcetype=xy
| eval env = if(host=="prod1", "PROD", "INT")
| table IREFFECTIVEDATE IRLOANRATE env
| head 1
| eval single_value="IREFFECTIVEDATE : ".IREFFECTIVEDATE." | IRLOANRATE : ".IRLOANRATE." |  Environment : ".env"
| fields single_value
| sort 0 _time
| streamstats current=f last(IREFFECTIVEDATE) as priorDate last(_time) as priorTime by env
| where NOT (IREFFECTIVEDATE=priorDate)
| mvcombine single_value delim="
"
| nomv single_value&lt;/LI-CODE&gt;
&lt;P&gt;Streamstats recognizes the changing value but it needs to be split by env.&lt;/P&gt;
&lt;P&gt;Any ideas please?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 16:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588182#M204837</guid>
      <dc:creator>Fe-atSplunk</dc:creator>
      <dc:date>2022-03-09T16:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Field value changes for two environments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588186#M204838</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| streamstats current=f global=f last(IREFFECTIVEDATE) as priorDate last(_time) as priorTime by env&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 09 Mar 2022 08:54:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588186#M204838</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-03-09T08:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Field value changes for two environments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588249#M204861</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response but it doesn't do anything. The previous event is PROD and the next one is INT, it still creates an incident event though the value of INT is what it always is.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 15:20:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588249#M204861</guid>
      <dc:creator>Fe-atSplunk</dc:creator>
      <dc:date>2022-03-09T15:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Field value changes for two environments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588253#M204862</link>
      <description>&lt;P&gt;Your search is selecting just one event (as it uses "| head 1").&amp;nbsp; How are you comparing two&amp;nbsp;&lt;SPAN&gt;IREFFECTIVEDATE values?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 15:47:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588253#M204862</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2022-03-09T15:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Field value changes for two environments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588254#M204863</link>
      <description>&lt;P&gt;Here is a runanywhere example showing it working&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| gentimes start=-1 increment=1h
| rename starttime as _time
| rename endhuman as IREFFECTIVEDATE
| eval env=mvindex(split("PROD|INT","|"),random()%2)
| streamstats current=f global=f last(IREFFECTIVEDATE) as priorDate last(_time) as priorTime by env
| fieldformat priorTime=strftime(priorTime,"%F %T")&lt;/LI-CODE&gt;&lt;P&gt;Obviously, if it isn't working for you, something else is amiss!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 15:57:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588254#M204863</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-03-09T15:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Field value changes for two environments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588258#M204865</link>
      <description>&lt;P&gt;For better visibility I'm showing in Statistics what was sent last (as we get those alerts once an hour). Looking back further I get lost of Events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As seen here there are two events per hour, one PROD, one INT but nothing changes from the last entry&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FeatSplunk_0-1646841665624.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18396i9E681ABC82BE0DCF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="FeatSplunk_0-1646841665624.png" alt="FeatSplunk_0-1646841665624.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 16:01:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588258#M204865</guid>
      <dc:creator>Fe-atSplunk</dc:creator>
      <dc:date>2022-03-09T16:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: Field value changes for two environments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588261#M204866</link>
      <description>&lt;P&gt;What's the time range you use in your alert? Last two hours?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 16:04:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588261#M204866</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2022-03-09T16:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Field value changes for two environments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588263#M204867</link>
      <description>&lt;P&gt;That's a good point, the alerts is looking back at the last one hour so it doesn't have anything to compare to. I'll try it with 2 hours. The problem is it takes 2 hours to wait for results&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 16:09:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588263#M204867</guid>
      <dc:creator>Fe-atSplunk</dc:creator>
      <dc:date>2022-03-09T16:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Field value changes for two environments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588265#M204869</link>
      <description>&lt;P&gt;Based on samples, you're receiving events around 13th minute of every hour so you can setup your alert to run shortly after that (e.g. run on 15th minute) with time-range of last 120 minute so that you'll cover data for this hour and last hour and get your alert sooner.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 16:15:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588265#M204869</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2022-03-09T16:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Field value changes for two environments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588902#M205092</link>
      <description>&lt;P&gt;Sorry that still doesn't work. At the moment the last two logs are both Prod and Stats show one event so it would still trigger an alert even though the value hasn't changed. Any ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 09:48:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-field-value-changes-for-two-environments/m-p/588902#M205092</guid>
      <dc:creator>Fe-atSplunk</dc:creator>
      <dc:date>2022-03-14T09:48:57Z</dc:date>
    </item>
  </channel>
</rss>

