Splunk Search

Filter using delta command

bmer
Explorer

Iam using 👇 splunk with delta command

 

 

 

 

 

 

index=xxxx source=xxxx rcrdType=xxx | timechart span=1h avg(requestSize) avg(responseSize)|delta avg(requestSize) |delta avg(responseSize)

 

 

 

 

 

bmer_0-1721558699774.png

I need to modify the query to ONLY include those events where either delta avg(requestSize)  OR delta avg(responseSize) OR both are positive

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

| where 'delta(avg(requestSize))' > 0 OR 'delta(avg(responseSize))' > 0

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

| where 'delta(avg(requestSize))' > 0 OR 'delta(avg(responseSize))' > 0
0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...