All Apps and Add-ons

Getting difference of two string values and calculating percentage

sowmya_kn
New Member

There are two strings "abc" and "xyz", some values are assigned to the strings;
suppose say
abc: 50 and xyz: 45

I want to write a quarry which yields a result like

Result = (abc-xyz)
and compare if result >= 75%

Please help me in this.Thanks in advance.

0 Karma

kristian_kolb
Ultra Champion

Your question is lacking a bit of information;

  • 75% of what?
  • Is abc always larger than xyz?

Anyway, here are a few examples of some arithmetic operations, but you should look up these pages as well;

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Eval
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions

your search here | eval diff = abc - xyz |



your search here | eval absdiff = abs(abc - xyz) |



your search here | eval ratio = xyz/abc |



your search here | eval ratio = xyz/abc | where ratio >=0.75

/K

0 Karma

kristian_kolb
Ultra Champion

So the last of my examples should fit you nicely. Please upvote and/or mark the answer as accepted if your problem was solved.

/K

0 Karma

sowmya_kn
New Member

75% of abc
yes abc is always larger than xyz

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...