<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Group results by range values in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95405#M24624</link>
    <description>&lt;P&gt;Another solution is to group by range, e.g:&lt;BR /&gt;
    search | chart count by duration span=5&lt;/P&gt;</description>
    <pubDate>Mon, 28 May 2018 12:33:45 GMT</pubDate>
    <dc:creator>moisesroth</dc:creator>
    <dc:date>2018-05-28T12:33:45Z</dc:date>
    <item>
      <title>Group results by range values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95400#M24619</link>
      <description>&lt;P&gt;I'm sure there is probably an answer this in the splunk base but I am having issues with what I want to call what I am attempting to do so therefore searching on it is somewhat difficult. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Essentially I want to pull all the duration values for a process that executes multiple times a day and group it based upon performance falling withing multiple windows.  I.e.  "Fastest" would be duration &amp;lt; 5 seconds.  "Fast" would be duration 5 seconds or more but less than, say, 20.  "Slow" would be anything 20 seconds or longer but less than, say, a minute, or 60 seconds, and "Painful" would be anything 60 seconds or longer.&lt;/P&gt;

&lt;P&gt;Essentially a report of &lt;BR /&gt;&lt;BR /&gt;
===============&lt;BR /&gt;&lt;BR /&gt;
|Group Class      | Count |&lt;BR /&gt;&lt;BR /&gt;
| Fastest             | 1987  |&lt;BR /&gt;&lt;BR /&gt;
| Fast                  |  500   |&lt;BR /&gt;&lt;BR /&gt;
| Slow                 |    27   |&lt;BR /&gt;&lt;BR /&gt;
| Slowest             |      5   |&lt;BR /&gt;&lt;/P&gt;

&lt;P&gt;Ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2013 17:02:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95400#M24619</guid>
      <dc:creator>tyronetv</dc:creator>
      <dc:date>2013-01-22T17:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Group results by range values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95401#M24620</link>
      <description>&lt;P&gt;Something like this (assuming the field your interested in is called 'dur') :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;your search here&amp;gt; 
| eval speed=case(dur&amp;lt;5,"Fastest",dur&amp;lt;20,"Fast",dur&amp;lt;60,"Slow",1=1,"Painful)
| stats count by speed
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The case statement exits on the 1st match, so the last statement :&lt;BR /&gt;&lt;BR /&gt;
 &lt;CODE&gt;1=1,"Painful"&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;acts as a default&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2013 17:29:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95401#M24620</guid>
      <dc:creator>jonuwz</dc:creator>
      <dc:date>2013-01-22T17:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Group results by range values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95402#M24621</link>
      <description>&lt;P&gt;Rangemap? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2013 18:43:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95402#M24621</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-01-22T18:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Group results by range values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95403#M24622</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;search | rangemap field=duration Slowest=0-5 Slow=5-27 Fast=27-500 Fastest=500-10000
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 22 Jan 2013 20:16:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95403#M24622</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2013-01-22T20:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: Group results by range values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95404#M24623</link>
      <description>&lt;P&gt;I believe it's the other way round, low durations are fastest&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 07:50:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95404#M24623</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-01-23T07:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Group results by range values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95405#M24624</link>
      <description>&lt;P&gt;Another solution is to group by range, e.g:&lt;BR /&gt;
    search | chart count by duration span=5&lt;/P&gt;</description>
      <pubDate>Mon, 28 May 2018 12:33:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-results-by-range-values/m-p/95405#M24624</guid>
      <dc:creator>moisesroth</dc:creator>
      <dc:date>2018-05-28T12:33:45Z</dc:date>
    </item>
  </channel>
</rss>

