- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
bmer
Explorer
07-21-2024
03:49 AM
Iam using 👇 splunk with delta command
index=xxxx source=xxxx rcrdType=xxx | timechart span=1h avg(requestSize) avg(responseSize)|delta avg(requestSize) |delta avg(responseSize)
I need to modify the query to ONLY include those events where either delta avg(requestSize) OR delta avg(responseSize) OR both are positive
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ITWhisperer

SplunkTrust
07-21-2024
03:53 AM
Try something like this
| where 'delta(avg(requestSize))' > 0 OR 'delta(avg(responseSize))' > 0
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ITWhisperer

SplunkTrust
07-21-2024
03:53 AM
Try something like this
| where 'delta(avg(requestSize))' > 0 OR 'delta(avg(responseSize))' > 0
