Hi All,
Basically what I'm trying to do here is there will a data as below
This is the sample data(The real data may be any numbers and the employees also any nymbers)
Employee1 Points Rank
Ram 1100 1
Girish 570 2
Mahesh 500 3
Lalith 500 3
Tanvie 200 4
Raj 100 5
Vishal 100 5
Yogee 100 5
so I want to write a splunk search to give the Ranks to the employees based on the Points.
Can you please help me to write this splunk search?
Regards,
Thippesh
Do it this way -
< your search > | streamstats current=f window=1 last(Points) as prevPoints | fillnull value=0 prevPoints | eval tempRank=if(Points=prevPoints,0,1) | streamstats sum(tempRank) as Rank | table Employee1 Points Rank
Do it this way -
< your search > | streamstats current=f window=1 last(Points) as prevPoints | fillnull value=0 prevPoints | eval tempRank=if(Points=prevPoints,0,1) | streamstats sum(tempRank) as Rank | table Employee1 Points Rank
Thanks Dinesh... it worked as expected.