Splunk Enterprise

table dataset

sarit_s
Communicator

Hello,

The query above calculates some fields for period of time as at the time picker
also, we have an alert which every 6 minutes the values for 2 minuets
i want to save the results of the alert and at the end calculate the results of a whole week

i saw that there is an option to use table dataset

my question is if table dataset is the right option, if yes - how can i do it
if not, what is the best way to achieve my goal 

| stats count as Total_Requests 
    count(eval(Request_Status=500 OR Request_Status=501 OR Request_Status=502 OR Request_Status=503 OR Request_Status=599 OR F5_statusCode=0 OR F5_statusCode="connection limit")) as Requests_Returned_Errors
    count(eval(Request_Status=504 OR F5_serverTime>20000)) as Requests_Returned_Timeouts 
    by API 

| fields API Total_Requests Requests_Returned_Errors Requests_Returned_Timeouts 
| lookup APIs_Owners.csv API OUTPUT Owner 
| eval
    TotalErrors=Requests_Returned_Errors+Requests_Returned_Timeouts,
    SLOTotal=round((Total_Requests-TotalErrors)/Total_Requests*100,2),
    Owner = if(isnotnull(Owner) , Owner ,"null - edit lookup") 
| fields API Total_Requests TotalErrors Requests_Returned_Errors Requests_Returned_Timeouts SLO* Owner

 thanks

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 4)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

SOC Modernization: How Automation and Splunk SOAR are Shaping the Next-Gen Security ...

Security automation is no longer a luxury but a necessity. Join us to learn how Splunk ES and SOAR empower ...