Splunk Search

How do i write a query on SPL to have a flag when next value of an event is greater then the precedence value?

royimad
Builder

How do i write a query on SPL to have a flag when next value on events is greater then the precedence value?

Hereby an example and the expected Result , values are from 1 to 100 and results should be zero or one when next value is greater then precedence value

>     event 1: value 1  [ Result:0]
>     event 2: value 2  [ Result:1]
>     event 3: value 2  [ Result:0]
>     event 4: value 2  [ Result:0]
>     event 5: value 3  [ Result:1]
>     event 6: value 3  [ Result:0]
>     event 7: value 1  [ Result:0]
>     event 8: value 1  [ Result:0]
>     event 9: value 2  [ Result:1]
>     event 10:value 2  [ Result:0]
0 Karma
1 Solution

Matthias_BY
Communicator

Hi,

  • | delta

then you can make a eval with if statement. eval result= if(delta=0, 0, 1)

if the delta value is 0 assign 0 every other value assign 1

br
matthias

View solution in original post

Matthias_BY
Communicator

Hi,

  • | delta

then you can make a eval with if statement. eval result= if(delta=0, 0, 1)

if the delta value is 0 assign 0 every other value assign 1

br
matthias

Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...