Splunk Search

How do i write a query on SPL to have a flag when next value of an event is greater then the precedence value?

royimad
Builder

How do i write a query on SPL to have a flag when next value on events is greater then the precedence value?

Hereby an example and the expected Result , values are from 1 to 100 and results should be zero or one when next value is greater then precedence value

>     event 1: value 1  [ Result:0]
>     event 2: value 2  [ Result:1]
>     event 3: value 2  [ Result:0]
>     event 4: value 2  [ Result:0]
>     event 5: value 3  [ Result:1]
>     event 6: value 3  [ Result:0]
>     event 7: value 1  [ Result:0]
>     event 8: value 1  [ Result:0]
>     event 9: value 2  [ Result:1]
>     event 10:value 2  [ Result:0]
0 Karma
1 Solution

Matthias_BY
Communicator

Hi,

  • | delta

then you can make a eval with if statement. eval result= if(delta=0, 0, 1)

if the delta value is 0 assign 0 every other value assign 1

br
matthias

View solution in original post

Matthias_BY
Communicator

Hi,

  • | delta

then you can make a eval with if statement. eval result= if(delta=0, 0, 1)

if the delta value is 0 assign 0 every other value assign 1

br
matthias

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...