<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic count(eval(execution-time)&amp;gt;1000) not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/count-eval-execution-time-gt-1000-not-working/m-p/685772#M233976</link>
    <description>&lt;P&gt;when I run below query I am not able to get the&amp;nbsp;sla_violation_count&lt;/P&gt;
&lt;P&gt;index=* execution-time=* uri="v1/validatetoken"&amp;nbsp; | stats count as total_calls, count(eval(execution-time &amp;gt; SLA)) as sla_violation_count&lt;/P&gt;
&lt;P&gt;total_calls are displaying as 1 but not able to get&amp;nbsp;sla_violation_count&lt;/P&gt;
&lt;P&gt;pasting the results below for the reference&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{ 
   datacenter: aus
   env: qa
   execution-time: 2145
   thread: http-nio-8080-exec-2
   uri: v1/validatetoken
   uriTemplate: v1/validatetoken
}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Apr 2024 09:04:01 GMT</pubDate>
    <dc:creator>VamshiBavu</dc:creator>
    <dc:date>2024-04-29T09:04:01Z</dc:date>
    <item>
      <title>count(eval(execution-time)&gt;1000) not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/count-eval-execution-time-gt-1000-not-working/m-p/685772#M233976</link>
      <description>&lt;P&gt;when I run below query I am not able to get the&amp;nbsp;sla_violation_count&lt;/P&gt;
&lt;P&gt;index=* execution-time=* uri="v1/validatetoken"&amp;nbsp; | stats count as total_calls, count(eval(execution-time &amp;gt; SLA)) as sla_violation_count&lt;/P&gt;
&lt;P&gt;total_calls are displaying as 1 but not able to get&amp;nbsp;sla_violation_count&lt;/P&gt;
&lt;P&gt;pasting the results below for the reference&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{ 
   datacenter: aus
   env: qa
   execution-time: 2145
   thread: http-nio-8080-exec-2
   uri: v1/validatetoken
   uriTemplate: v1/validatetoken
}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 09:04:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/count-eval-execution-time-gt-1000-not-working/m-p/685772#M233976</guid>
      <dc:creator>VamshiBavu</dc:creator>
      <dc:date>2024-04-29T09:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: count(eval(execution-time)&gt;1000) not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/count-eval-execution-time-gt-1000-not-working/m-p/685776#M233978</link>
      <description>&lt;P&gt;The stats(eval()) syntax can be confusing sometimes and is definitely underdocummented.&lt;/P&gt;&lt;P&gt;I don't like its implicit behaviour so I prefer doing stuff "the long way"&lt;/P&gt;&lt;PRE&gt;| eval is_sla_violated=if(execution-time &amp;gt; SLA,1,0)&lt;BR /&gt;| stats sum(is_sla_violated) as sla_violation_count&lt;/PRE&gt;&lt;P&gt;Of course instead of doing 1/0 and using sum you can do anything/null() and use count.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 08:12:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/count-eval-execution-time-gt-1000-not-working/m-p/685776#M233978</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-29T08:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: count(eval(execution-time)&gt;1000) not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/count-eval-execution-time-gt-1000-not-working/m-p/685778#M233979</link>
      <description>&lt;P&gt;Try with the fieldname in single quotes&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ndex=* execution-time=* uri="v1/validatetoken"  | stats count as total_calls, count(eval('execution-time' &amp;gt; SLA)) as sla_violation_count&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 29 Apr 2024 08:17:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/count-eval-execution-time-gt-1000-not-working/m-p/685778#M233979</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-04-29T08:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: count(eval(execution-time)&gt;1000) not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/count-eval-execution-time-gt-1000-not-working/m-p/685779#M233980</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;thank you ,you made my day&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 09:42:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/count-eval-execution-time-gt-1000-not-working/m-p/685779#M233980</guid>
      <dc:creator>VamshiBavu</dc:creator>
      <dc:date>2024-04-29T09:42:14Z</dc:date>
    </item>
  </channel>
</rss>

