Dashboards & Visualizations

IF/CASE for multiple variables

klaudiac
Path Finder

Hi guys, 

Looking for a bit of help because I confused myself at this point and can't think logically 😞

I'm creating a search where I can show uploads vs downloads, and the criteria is as follow:

*if bytes_in (download) is more than 70% of all the bytes for that user, then the main action is data download and I want to add a column "alert" with a value "download"

*if bytes_out (upload) is more than 70% of all the bytes for that user, then the main action is data upload and I want to add to the column "alert" that it's going to be an "upload" 

*if the bytes in and our are within 20% of the even split, then the value in the "alert" column will be no action.
if the split is even, then "no action". 


Now, how do I do it in Splunk?? 

Labels (1)
0 Karma
1 Solution

inventsekar
SplunkTrust
SplunkTrust
index=indexName
| eval user_bytes_perc_download = (bytes_in/all_bytes_user)*100
| eval user_bytes_perc_upload = (bytes_out/all_bytes_user)*100
| eval alert=case(user_bytes_perc_download > 70,"download", user_bytes_perc_upload > 70,"upload", user_bytes_perc_download <20 AND user_bytes_perc_upload < 20, "no action")

if the bytes in and our are within 20% of the even split -  I got confused with this, so the query is as per my understanding. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

inventsekar
SplunkTrust
SplunkTrust
index=indexName
| eval user_bytes_perc_download = (bytes_in/all_bytes_user)*100
| eval user_bytes_perc_upload = (bytes_out/all_bytes_user)*100
| eval alert=case(user_bytes_perc_download > 70,"download", user_bytes_perc_upload > 70,"upload", user_bytes_perc_download <20 AND user_bytes_perc_upload < 20, "no action")

if the bytes in and our are within 20% of the even split -  I got confused with this, so the query is as per my understanding. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

klaudiac
Path Finder

Nevermind - I have it 🙂 

Thanks so much for your help! 

0 Karma

klaudiac
Path Finder

Thanks so much, almost there 🙂
I should have specified better - the equal split would be 50-50% between in and out.  So anything that's within the 30% (not 20 - sorry, I'm losing it today) margin would be "no action" e.g. 60% are uploads and  40% are downloads = "no action" 

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...