Splunk Search

Greater Than & Less Than or Equal To

IRHM73
Motivator

Hi, I wonder whether someone may be able to help me please.

I've created the line below which is part of a bigger query.

|eval groupduration=case(duration<=300,"<5 minutes", >300 AND <=600, "Between 5 & 10 Minutes")

The problem I have is around this part >300 AND <=600, where I would like say where "The value is greater than 300 But Less Than Or Equal to 600".

I've spent quite a while searching for a solution, but I've been unable to find one.

I just wondered whether someone may be able to look at this please and let me know where I've gone wrong.

Many thanks and kind regards

Chris

0 Karma
1 Solution

javiergn
Super Champion

You are missing the duration variable in your second case statement:

|eval groupduration=case(duration<=300, "<5 minutes", duration>300 AND duration<=600, "Between 5 & 10 Minutes")

View solution in original post

javiergn
Super Champion

You are missing the duration variable in your second case statement:

|eval groupduration=case(duration<=300, "<5 minutes", duration>300 AND duration<=600, "Between 5 & 10 Minutes")

IRHM73
Motivator

Hi @javiergn, thank you for this, I knew it would be something simple.

Many thanks and kind regards

Chris

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...