Splunk Search

Compare current and last one hour event value in same search.

vaibhavvijay9
New Member

Hi All,

I have to monitor the queues. And for that I have made the basic dashboard where it shows the details. Details are like : queueName, inTotalMsgs, outTotalMsgs, pendingMsgCount and dedup the queueName.

Now, what I want is (another search [new]): "If the current pendingMsg count is greater than or equal to the last one hour count, then display the queueName with label - 'Queue with no processing since last one hour' "
(OR we can say the outTotalMsgs is same for now and last one hour event)

Example :
My basic new search no dedup applied, but currently I have written only one queueName :

..... | xmlkv | table _time, qName, pendingMsgCount, inTotalMsgs, outTotalMsgs

Timestamp (last 60 minutes) - (22/02/2019 06:58:00.000 to 22/02/2019 07:58:13.000)

Results : only one queueName (124 events)

  • first two :
    alt text

  • last two :
    alt text

So, for this queueName, the pendingMsg count is same and hence it should be displayed in results for dashboard - 'Queue with no processing since last one hour'.

I am not able to achieve this, please help!

Thanks in advance!

0 Karma

renjith_nair
Legend

@vaibhavvijay9 ,

Try

 | xmlkv | table _time, qName, pendingMsgCount, inTotalMsgs, outTotalMsgs|dedup _time,qName
 |sort _time,qName
 |streamstats last(pendingMsgCount) as prev current=f by qName
 |eval diff=pendingMsgCount-prev| where diff>=0

This should give you Q names which haven't processed in last hour

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...