Splunk Search
Highlighted

How to compare data for a scheduled search for the past 1 hour with the previous 24 hours?

Communicator

Hi,

I have two scheduled searches that run every 1 hour with retroactive time interval (earliest = -1h). I need to perform a comparison if a certain condition occurs within this range, so I have to increase the retroactive time (earliest = -24h), but still keep the condition of the events that occurred within the 1 hour interval. How do I do this?

0 Karma
Highlighted

Re: How to compare data for a scheduled search for the past 1 hour with the previous 24 hours?

Contributor

Use bucket spanning to set your sample rate to 1 hour

| bucket _time span=1h

View solution in original post

Highlighted

Re: How to compare data for a scheduled search for the past 1 hour with the previous 24 hours?

Communicator

Hi,

It works, tks.

Rodrigo Ribeiro

0 Karma