<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Auto Group Result in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Auto-Group-Result/m-p/38807#M8847</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I would like to group my product based on weight.&lt;/P&gt;

&lt;P&gt;Sample logs are:&lt;/P&gt;

&lt;P&gt;Product ID  |   Weight&lt;/P&gt;

&lt;P&gt;00368001a1  |   1.4kg   &lt;/P&gt;

&lt;P&gt;00368001d1  |   1.3kg&lt;/P&gt;

&lt;P&gt;00368002a1  |   0.9kg&lt;/P&gt;

&lt;P&gt;00368003a1  |   2.0kg&lt;/P&gt;

&lt;P&gt;00368004a1  |   1.5kg&lt;/P&gt;

&lt;P&gt;I need to set weight(+ or - between 0.5).&lt;BR /&gt;
0.5 - 1.4kg as A and 1.5 - 2.4kg is group as B&lt;BR /&gt;
Instead of manually defining as what I am currently doing:&lt;BR /&gt;
| eval total_weight=case(weight&amp;lt;0.5,"A",weight&amp;lt;1.4,"B",weight&amp;lt;2.4,"C") | stats count by total_weight&lt;BR /&gt;
Any help is greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:22:02 GMT</pubDate>
    <dc:creator>yap</dc:creator>
    <dc:date>2020-09-28T13:22:02Z</dc:date>
    <item>
      <title>Auto Group Result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Auto-Group-Result/m-p/38807#M8847</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I would like to group my product based on weight.&lt;/P&gt;

&lt;P&gt;Sample logs are:&lt;/P&gt;

&lt;P&gt;Product ID  |   Weight&lt;/P&gt;

&lt;P&gt;00368001a1  |   1.4kg   &lt;/P&gt;

&lt;P&gt;00368001d1  |   1.3kg&lt;/P&gt;

&lt;P&gt;00368002a1  |   0.9kg&lt;/P&gt;

&lt;P&gt;00368003a1  |   2.0kg&lt;/P&gt;

&lt;P&gt;00368004a1  |   1.5kg&lt;/P&gt;

&lt;P&gt;I need to set weight(+ or - between 0.5).&lt;BR /&gt;
0.5 - 1.4kg as A and 1.5 - 2.4kg is group as B&lt;BR /&gt;
Instead of manually defining as what I am currently doing:&lt;BR /&gt;
| eval total_weight=case(weight&amp;lt;0.5,"A",weight&amp;lt;1.4,"B",weight&amp;lt;2.4,"C") | stats count by total_weight&lt;BR /&gt;
Any help is greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:22:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Auto-Group-Result/m-p/38807#M8847</guid>
      <dc:creator>yap</dc:creator>
      <dc:date>2020-09-28T13:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Group Result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Auto-Group-Result/m-p/38808#M8848</link>
      <description>&lt;P&gt;Bucket with a span of 1 would give you +/-0.5kg values, you just have to strip off the "kg" first to make it numerical. I'm not sure if you can do 0.5-1.5 groups though, it tends to create 0-1 buckets instead. If all else fails, shift your weights up by half a kilo &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Feb 2013 09:27:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Auto-Group-Result/m-p/38808#M8848</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-02-21T09:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Group Result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Auto-Group-Result/m-p/38809#M8849</link>
      <description>&lt;P&gt;Thanks Martin&lt;/P&gt;</description>
      <pubDate>Thu, 21 Feb 2013 09:35:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Auto-Group-Result/m-p/38809#M8849</guid>
      <dc:creator>yap</dc:creator>
      <dc:date>2013-02-21T09:35:30Z</dc:date>
    </item>
  </channel>
</rss>

