Iam using 👇 splunk with delta command
index=xxxx source=xxxx rcrdType=xxx | timechart span=1h avg(requestSize) avg(responseSize)|delta avg(requestSize) |delta avg(responseSize)
I need to modify the query to ONLY include those events where either delta avg(requestSize) OR delta avg(responseSize) OR both are positive
Try something like this
| where 'delta(avg(requestSize))' > 0 OR 'delta(avg(responseSize))' > 0
Try something like this
| where 'delta(avg(requestSize))' > 0 OR 'delta(avg(responseSize))' > 0