<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to search for multiple cases? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-multiple-cases/m-p/621664#M216093</link>
    <description>&lt;P&gt;Hi community,&lt;/P&gt;
&lt;P&gt;I have 2 data sources, 1 from a csv to get the list of district (include number of population according to each district). Other sources come from PostgreSQL. The common info is the district.&lt;/P&gt;
&lt;P&gt;After a lookup csv, I have the list of district, for ex 6 districts.&lt;/P&gt;
&lt;P&gt;Knowing that 5 districts have the equivalent population (ex 500), another district has only 100 people living there.&lt;/P&gt;
&lt;P&gt;I want to do the span later, to count the activities of each district and send an alert if there is no activity of a district. But the difficulty is the span is not the same amongs all the districts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to let span =1 day for 5 districts which have 500 people, and 5 days for the district with 100 population.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In a same search, can I do a case or if else to separate 2 cases?&lt;/P&gt;
&lt;P&gt;Here is what I'm doing:&lt;/P&gt;
&lt;P&gt;|dbxquery connection="database" query=" SELECT * FROM table"&lt;BR /&gt;|lookup lookup.csv numero OUTPUT DISTRICT&lt;BR /&gt;|eval list_district = "1,2,3,4,5,6"&lt;BR /&gt;|eval split_list_district= split(list_district,",")&lt;BR /&gt;|mvexpand split_list_district&lt;BR /&gt;|where DISTRICT=split_list_district&lt;BR /&gt;|eval _time=strptime(time_receive,"%Y-%m-%dT%H:%M:%S.%N")&lt;BR /&gt;|eval _comment="Can we do something here to separate 2 cases"&lt;BR /&gt;|bin _time span=1h&lt;BR /&gt;|chart sum(count_activity) as count by _time DISTRICT&lt;/P&gt;
&lt;P&gt;......&lt;/P&gt;</description>
    <pubDate>Tue, 22 Nov 2022 14:34:54 GMT</pubDate>
    <dc:creator>Julia1231</dc:creator>
    <dc:date>2022-11-22T14:34:54Z</dc:date>
    <item>
      <title>How to search for multiple cases?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-multiple-cases/m-p/621664#M216093</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;
&lt;P&gt;I have 2 data sources, 1 from a csv to get the list of district (include number of population according to each district). Other sources come from PostgreSQL. The common info is the district.&lt;/P&gt;
&lt;P&gt;After a lookup csv, I have the list of district, for ex 6 districts.&lt;/P&gt;
&lt;P&gt;Knowing that 5 districts have the equivalent population (ex 500), another district has only 100 people living there.&lt;/P&gt;
&lt;P&gt;I want to do the span later, to count the activities of each district and send an alert if there is no activity of a district. But the difficulty is the span is not the same amongs all the districts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to let span =1 day for 5 districts which have 500 people, and 5 days for the district with 100 population.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In a same search, can I do a case or if else to separate 2 cases?&lt;/P&gt;
&lt;P&gt;Here is what I'm doing:&lt;/P&gt;
&lt;P&gt;|dbxquery connection="database" query=" SELECT * FROM table"&lt;BR /&gt;|lookup lookup.csv numero OUTPUT DISTRICT&lt;BR /&gt;|eval list_district = "1,2,3,4,5,6"&lt;BR /&gt;|eval split_list_district= split(list_district,",")&lt;BR /&gt;|mvexpand split_list_district&lt;BR /&gt;|where DISTRICT=split_list_district&lt;BR /&gt;|eval _time=strptime(time_receive,"%Y-%m-%dT%H:%M:%S.%N")&lt;BR /&gt;|eval _comment="Can we do something here to separate 2 cases"&lt;BR /&gt;|bin _time span=1h&lt;BR /&gt;|chart sum(count_activity) as count by _time DISTRICT&lt;/P&gt;
&lt;P&gt;......&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 14:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-multiple-cases/m-p/621664#M216093</guid>
      <dc:creator>Julia1231</dc:creator>
      <dc:date>2022-11-22T14:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to search for multiple cases?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-multiple-cases/m-p/621731#M216120</link>
      <description>&lt;P&gt;Assuming there's a field "population" in the data, you can use &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/DateandTimeFunctions#relative_time.28X.2CY.29" target="_blank" rel="noopener"&gt;relative_time&lt;/A&gt;. &amp;nbsp;Something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|dbxquery connection="database" query=" SELECT * FROM table"
|lookup lookup.csv numero OUTPUT DISTRICT
|eval list_district = "1,2,3,4,5,6"
|eval split_list_district= split(list_district,",")
|mvexpand split_list_district
|where DISTRICT=split_list_district
|eval _time=strptime(time_receive,"%Y-%m-%dT%H:%M:%S.%N")
| eval cutoff = if(population &amp;lt; 120, relative_time(now(), "-1d"), relative_time(now(), "-5d")) ``` use 120 to allow margin ```
| where _time &amp;gt; cutoff
|bin _time span=1h
|chart sum(count_activity) as count by _time DISTRICT&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 16:38:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-multiple-cases/m-p/621731#M216120</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-11-22T16:38:15Z</dc:date>
    </item>
  </channel>
</rss>

