Splunk Search

Combine Values into one event then search if one of the values are contained

geraldcontreras
Path Finder

Hi,
Thanks in advance

This is hard one to put well in the title

Basically i have sets of data which contain Students Scores for tests. Students can take these tests multiple times.
I need a search that will show only events where the student has never scroed greater than 80

Sample Data (fields "Display_Name" and "result":

Display_Name result
John_Doe 20
John_Doe 60
John_Doe 80
Jane_Doe 95
Jack_Doe 20

Results i need (as he is the only person not to have scored 80 or higher:
Jack_Doe

i cant just simply use
"where result < 80"
because then John_doe will be included.

I need something that will exclude someone who has scored 80 or higher.

I have tried all matter of combinations, which i wont list as i find sometimes its best for people to approach without prior conception.

Thanks you all

0 Karma
1 Solution

geraldcontreras
Path Finder

I found the answer by using max
it was staring me in the face the whole time

| stats max(Score) as result by Display_Name | where result < 80

must of been a Friday! 😄

View solution in original post

0 Karma

geraldcontreras
Path Finder

I found the answer by using max
it was staring me in the face the whole time

| stats max(Score) as result by Display_Name | where result < 80

must of been a Friday! 😄

0 Karma

renjith_nair
Legend

@geraldcontreras , converted your comment to answer. You may accept it as answer and close the thread 🙂

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...