<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to have 2 stats in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-to-have-2-stats/m-p/193668#M55782</link>
    <description>&lt;P&gt;Your question is so vague it is impossible to say but I am reasonably sure that you will need to use &lt;CODE&gt;eventstats&lt;/CODE&gt; to insert your first pass of &lt;CODE&gt;stats&lt;/CODE&gt; values into your events and then use a final &lt;CODE&gt;stats&lt;/CODE&gt; later, maybe like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| dbquery PROD-UOL7-MANUT-MONITORACAO 
"select 
dat_collect_transaction as "data",
TO_CHAR(dat_collect_transaction, 'DD/MM') as "Date",
dat_update as "update",
idt_inscription_account as "conta"
from collect_transaction
where idt_payment_method = 221 and dat_collect_transaction &amp;gt; sysdate -5 and dat_collect_transaction &amp;lt; sysdate-1"
| eval media=update-data
| eventstats avg(media) as Media
| eval Media = Media*2
| eval MediaTotal=tostring(Media, "duration")
| stats count(eval(media&amp;lt;MediaTotal)) as "Down" count(eval(media&amp;gt;MediaTotal)) as "Up" by Date
| table Date, Down, Up
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 06 Jul 2015 16:36:35 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-07-06T16:36:35Z</dc:date>
    <item>
      <title>how to have 2 stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-have-2-stats/m-p/193667#M55781</link>
      <description>&lt;P&gt;How can i have those 2 stats?&lt;/P&gt;

&lt;P&gt;| dbquery PROD-UOL7-MANUT-MONITORACAO &lt;BR /&gt;
"select &lt;BR /&gt;
dat_collect_transaction as \"data\",&lt;BR /&gt;
TO_CHAR(dat_collect_transaction, 'DD/MM') as \"Date\",&lt;BR /&gt;
dat_update as \"update\",&lt;BR /&gt;
idt_inscription_account as \"conta\"&lt;BR /&gt;
from collect_transaction&lt;BR /&gt;
where idt_payment_method = 221 and dat_collect_transaction &amp;gt; sysdate -5 and dat_collect_transaction &amp;lt; sysdate-1"&lt;BR /&gt;
| eval media=update-data&lt;BR /&gt;
| stats avg(media) as Media&lt;BR /&gt;
| eval Media = Media*2&lt;BR /&gt;
| eval MediaTotal=tostring(Media, "duration")&lt;BR /&gt;
| stats count(eval(media&amp;lt;MediaTotal)) as "Down" count(eval(media&amp;gt;MediaTotal)) as "Up" by Date&lt;BR /&gt;
| table Date, Down, Up&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:36:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-have-2-stats/m-p/193667#M55781</guid>
      <dc:creator>felipesewaybric</dc:creator>
      <dc:date>2020-09-29T06:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: how to have 2 stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-have-2-stats/m-p/193668#M55782</link>
      <description>&lt;P&gt;Your question is so vague it is impossible to say but I am reasonably sure that you will need to use &lt;CODE&gt;eventstats&lt;/CODE&gt; to insert your first pass of &lt;CODE&gt;stats&lt;/CODE&gt; values into your events and then use a final &lt;CODE&gt;stats&lt;/CODE&gt; later, maybe like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| dbquery PROD-UOL7-MANUT-MONITORACAO 
"select 
dat_collect_transaction as "data",
TO_CHAR(dat_collect_transaction, 'DD/MM') as "Date",
dat_update as "update",
idt_inscription_account as "conta"
from collect_transaction
where idt_payment_method = 221 and dat_collect_transaction &amp;gt; sysdate -5 and dat_collect_transaction &amp;lt; sysdate-1"
| eval media=update-data
| eventstats avg(media) as Media
| eval Media = Media*2
| eval MediaTotal=tostring(Media, "duration")
| stats count(eval(media&amp;lt;MediaTotal)) as "Down" count(eval(media&amp;gt;MediaTotal)) as "Up" by Date
| table Date, Down, Up
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 06 Jul 2015 16:36:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-have-2-stats/m-p/193668#M55782</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-07-06T16:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: how to have 2 stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-have-2-stats/m-p/193669#M55783</link>
      <description>&lt;P&gt;You're comparing a numeric value, media, to a string value, MediaTotal, which doesn't work.  Try comparing media to Media, although that should always yield "Down".  BTW, your search does not account for media==MediaTotal.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2015 16:36:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-have-2-stats/m-p/193669#M55783</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-07-06T16:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: how to have 2 stats</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-have-2-stats/m-p/193670#M55784</link>
      <description>&lt;P&gt;Thanks, this is the complete search, works like a charm:&lt;/P&gt;

&lt;P&gt;| dbquery PROD-UOL7-MANUT-MONITORACAO &lt;BR /&gt;
"select &lt;BR /&gt;
dat_collect_transaction as \"data\",&lt;BR /&gt;
TO_CHAR(dat_collect_transaction, 'DD/MM') as \"Date\",&lt;BR /&gt;
dat_update as \"update\",&lt;BR /&gt;
idt_inscription_account as \"conta\"&lt;BR /&gt;
from collect_transaction&lt;BR /&gt;
where idt_payment_method = 221 and dat_collect_transaction &amp;gt; sysdate -15 and dat_collect_transaction &amp;lt; sysdate-1"&lt;BR /&gt;
| eval intervalo=update-data&lt;BR /&gt;
| eventstats avg(intervalo) as Intervalo&lt;BR /&gt;
| eval Intervalo = Intervalo*2&lt;BR /&gt;
| stats count(eval(intervaloIntervalo)) as "Acima do tempo medio" values(conta) as Contas by Date&lt;BR /&gt;
| table Date, "Acima do tempo medio", "Dentro do tempo medio", Contas&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:36:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-have-2-stats/m-p/193670#M55784</guid>
      <dc:creator>felipesewaybric</dc:creator>
      <dc:date>2020-09-29T06:36:32Z</dc:date>
    </item>
  </channel>
</rss>

