<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search command. - in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683767#M233452</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;BR /&gt;How do i change the max column, in readable format like 40 mins , 30 mins or 1 hrs&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1712711384079.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30341iB63BC844B0E2F475/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1712711384079.png" alt="jaibalaraman_0-1712711384079.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2024 01:09:58 GMT</pubDate>
    <dc:creator>jaibalaraman</dc:creator>
    <dc:date>2024-04-10T01:09:58Z</dc:date>
    <item>
      <title>Search command. -</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683754#M233444</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I am not sure about this value risk score.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do i create dashboard tile for this fields&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1712703374369.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30338i8EE1872C4E31ECD5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1712703374369.png" alt="jaibalaraman_0-1712703374369.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 22:56:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683754#M233444</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2024-04-09T22:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Search command. -</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683755#M233445</link>
      <description>&lt;P&gt;max(), avg() and stdev() are all aggregation functions which you can include on a stats command in your search&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Aggregatefunctions" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Aggregatefunctions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 23:01:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683755#M233445</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-04-09T23:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Search command. -</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683757#M233446</link>
      <description>&lt;P&gt;Hi Thanks for the responce&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, i have gone through aggregate function, could you please help how to implement in the code&amp;nbsp;&lt;/P&gt;&lt;P&gt;Exp 1 -&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;chart eval(avg(size)/max(delay)) AS ratio BY host user&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;OR&amp;nbsp; &amp;nbsp; &amp;nbsp; timechart eval(round(avg(cpu_seconds),2)) BY processor&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1712704159039.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30339i39FC338228BD06C4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1712704159039.png" alt="jaibalaraman_0-1712704159039.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 23:09:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683757#M233446</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2024-04-09T23:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: Search command. -</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683759#M233447</link>
      <description>&lt;P&gt;That'll depends on what you want to show for your risk score. &amp;nbsp;Do you want to show max? &amp;nbsp;Do you want to show avg? &amp;nbsp;Is there a groupby field you want to use?&lt;/P&gt;&lt;P&gt;Note the excerpted examples from the document are very specific to the problem the examples are trying to illustrate. &amp;nbsp;It is not a substitute for you to describe your desired output. &amp;nbsp;If you don't tell people, volunteers would have no way to read your mind.&lt;/P&gt;&lt;P&gt;In the simplest form, you can experiment with something like&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| chart avg('event.Properties.riskScore')
  max('event.Properties.riskScore')
  min('event.Properties.riskScore')
  stdev('event.Properties.riskScore')&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But you already did this. &amp;nbsp;So, what is your desired output? &amp;nbsp;Alternatively, what is the use case you are trying to apply? &amp;nbsp;What is the business problem you are trying to solve/illustrate using this dashboard?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 00:27:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683759#M233447</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-04-10T00:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Search command. -</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683760#M233448</link>
      <description>&lt;P&gt;Yes i trying to find out max duration and the endpoint which is associated with&amp;nbsp;&lt;/P&gt;&lt;H2&gt;event.Properties.endpoint&lt;BR /&gt;&lt;BR /&gt;&lt;/H2&gt;&lt;H2&gt;event.Properties.duration.&lt;/H2&gt;</description>
      <pubDate>Wed, 10 Apr 2024 00:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683760#M233448</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2024-04-10T00:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: Search command. -</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683762#M233450</link>
      <description>&lt;LI-CODE lang="markup"&gt;| chart max('event.Properties.duration') by event.Properties.endpoint&lt;/LI-CODE&gt;&lt;P&gt;Something like this?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 00:50:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683762#M233450</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-04-10T00:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Search command. -</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683765#M233451</link>
      <description>&lt;P&gt;I tried the search, but not getting the max number&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1712711067486.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30340i6198C53734800599/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1712711067486.png" alt="jaibalaraman_0-1712711067486.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 01:04:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683765#M233451</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2024-04-10T01:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: Search command. -</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683767#M233452</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;BR /&gt;How do i change the max column, in readable format like 40 mins , 30 mins or 1 hrs&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1712711384079.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30341iB63BC844B0E2F475/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1712711384079.png" alt="jaibalaraman_0-1712711384079.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 01:09:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683767#M233452</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2024-04-10T01:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Search command. -</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683777#M233457</link>
      <description>&lt;P&gt;Instead of dealing with the messiness of a natural language, it might be better to use standard notation of duration, like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| fieldformat max(event.Properties.duration) = tostring('max(event.Properties.duration)', "duration")&lt;/LI-CODE&gt;&lt;P&gt;Instead of&amp;nbsp;&lt;SPAN&gt;40 mins , 30 mins or 1 hrs, you get 00:40:00, 00:30:00, 01:00:00, and so on.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 05:58:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-command/m-p/683777#M233457</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-04-10T05:58:43Z</dc:date>
    </item>
  </channel>
</rss>

