<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search multiple values from a single event where one value might be less than 800? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-values-from-a-single-event-where-one-value-might/m-p/619604#M215341</link>
    <description>&lt;P&gt;I have the following criteria from a single event that appears like:&lt;/P&gt;
&lt;P&gt;Time Event&lt;BR /&gt;11/4/22&lt;BR /&gt;4:10:28.000 AM&lt;BR /&gt;{ [-]&lt;BR /&gt;Total: 6656&lt;BR /&gt;srv110: 1002&lt;BR /&gt;srv111: 1105&lt;BR /&gt;srv112: 1007&lt;BR /&gt;srv113: 995&lt;BR /&gt;srv114: 1269&lt;BR /&gt;srv115: 1278&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;&amp;lt;My Query&amp;gt;| timechart span=1m values(srv*) will return the values as so:&lt;/P&gt;
&lt;TABLE width="763"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="97"&gt;_time&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv110)&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv111)&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv112)&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv113)&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv114)&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv115)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;11/4/2022 4:04&lt;/TD&gt;
&lt;TD&gt;1003&lt;/TD&gt;
&lt;TD&gt;1105&lt;/TD&gt;
&lt;TD&gt;1007&lt;/TD&gt;
&lt;TD&gt;996&lt;/TD&gt;
&lt;TD&gt;1268&lt;/TD&gt;
&lt;TD&gt;1278&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I need to return all of them as so even if any one of those values falls under 800 but also greater than -1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I attempted to transpose and search from there but I'm failing somewhere.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help or nudge in the right direction would be greatly appreciated.&amp;nbsp; Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Nov 2022 16:33:19 GMT</pubDate>
    <dc:creator>jasonhask</dc:creator>
    <dc:date>2022-11-04T16:33:19Z</dc:date>
    <item>
      <title>Search multiple values from a single event where one value might be less than 800?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-values-from-a-single-event-where-one-value-might/m-p/619604#M215341</link>
      <description>&lt;P&gt;I have the following criteria from a single event that appears like:&lt;/P&gt;
&lt;P&gt;Time Event&lt;BR /&gt;11/4/22&lt;BR /&gt;4:10:28.000 AM&lt;BR /&gt;{ [-]&lt;BR /&gt;Total: 6656&lt;BR /&gt;srv110: 1002&lt;BR /&gt;srv111: 1105&lt;BR /&gt;srv112: 1007&lt;BR /&gt;srv113: 995&lt;BR /&gt;srv114: 1269&lt;BR /&gt;srv115: 1278&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;&amp;lt;My Query&amp;gt;| timechart span=1m values(srv*) will return the values as so:&lt;/P&gt;
&lt;TABLE width="763"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="97"&gt;_time&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv110)&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv111)&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv112)&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv113)&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv114)&lt;/TD&gt;
&lt;TD width="111"&gt;values(srv115)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;11/4/2022 4:04&lt;/TD&gt;
&lt;TD&gt;1003&lt;/TD&gt;
&lt;TD&gt;1105&lt;/TD&gt;
&lt;TD&gt;1007&lt;/TD&gt;
&lt;TD&gt;996&lt;/TD&gt;
&lt;TD&gt;1268&lt;/TD&gt;
&lt;TD&gt;1278&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I need to return all of them as so even if any one of those values falls under 800 but also greater than -1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I attempted to transpose and search from there but I'm failing somewhere.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help or nudge in the right direction would be greatly appreciated.&amp;nbsp; Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 16:33:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-values-from-a-single-event-where-one-value-might/m-p/619604#M215341</guid>
      <dc:creator>jasonhask</dc:creator>
      <dc:date>2022-11-04T16:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple values from a single event where one value might be less than 800</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-values-from-a-single-event-where-one-value-might/m-p/619605#M215342</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/185588"&gt;@jasonhask&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please share _raw from the sample event?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=YOUR_INDEX | table _raw&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 08:47:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-values-from-a-single-event-where-one-value-might/m-p/619605#M215342</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2022-11-04T08:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple values from a single event where one value might be less than 800</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-values-from-a-single-event-where-one-value-might/m-p/619606#M215343</link>
      <description>&lt;P&gt;{"srv110": 1001, "srv111": 1104, "srvTotal": 6651, "srv112": 1006, "time": "2022-11-04T08:47:02Z", "srv113": 995, "srv114": 1268, "srv115": 1277}&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 08:49:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-values-from-a-single-event-where-one-value-might/m-p/619606#M215343</guid>
      <dc:creator>jasonhask</dc:creator>
      <dc:date>2022-11-04T08:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple values from a single event where one value might be less than 800</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-values-from-a-single-event-where-one-value-might/m-p/619611#M215346</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/185588"&gt;@jasonhask&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;YOUR_SEARCH
| bin span=1m _time 
| stats values(srv*) as srv* by _time 
| eval flag = 0 
| foreach srv* 
    [ eval flag = if(flag == 0 AND &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;&amp;lt;800 AND &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; &amp;gt; -1, 1 , flag)
        ] 
| where flag=1 
| fields - flag, srvTotal&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this will help you.&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;If any of my replies help you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 09:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-values-from-a-single-event-where-one-value-might/m-p/619611#M215346</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2022-11-04T09:26:45Z</dc:date>
    </item>
  </channel>
</rss>

