Splunk Search

How to compare when a field value changes from current to previous?

Glasses
Builder

I am looking to find events where IP address changes from previous to current, however using fist(ip) and last(ip) misses the events in between the first and last...

Ideally I am looking to find when a change occurs for the IP value and then look at the previous IP value... this comparison is then used to find ip geoloc and calc the speed = dist/time with haversine app.

Thank you

0 Karma
1 Solution

DalJeanis
Legend

Look at the streamstats command for this. Any tracking of change over time, streamstats is your go-to verb.

We'll assume there is a key called user.

your search that gets the records you want, with at least these fields  
| fields _time user someIP
| sort 0 _time 
| streamstats current=f last(someIP) as priorIP last(_time) as priorTime  by user
| where NOT (someIP=priorIP)
 ... the remainder of your search. 

View solution in original post

DalJeanis
Legend

Look at the streamstats command for this. Any tracking of change over time, streamstats is your go-to verb.

We'll assume there is a key called user.

your search that gets the records you want, with at least these fields  
| fields _time user someIP
| sort 0 _time 
| streamstats current=f last(someIP) as priorIP last(_time) as priorTime  by user
| where NOT (someIP=priorIP)
 ... the remainder of your search. 

Glasses
Builder

Wow that is awesome!!! Thanks

DalJeanis
Legend

You are quite welcome. streamstats processes the records in order, remembering only the records it has already seen, so you must sort the records in the order you want before you apply the command.

0 Karma

Glasses
Builder

so that is the purpose of sort 0 > return all results, thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...