Splunk Search

How to create a search to extract and compare values?

rajs115
Path Finder

Hi,

  I need help with below query search. Below is the sample logs.

Logs:

Conatainer: dev_test_cluster
CountRequired: 2
CountRunning: 1
FunctionName: dev_dd_app


I need to write a query for to compare the CountRequired and CountRunning values and show details when CountRunning is less than CountRequired.

Appreciate the help.

Labels (3)
Tags (1)
0 Karma
1 Solution

jamie00171
Communicator

Hi @rajs115 

 

Does something like this work for you:

 

index=<your index> sourcetype=<your sourcetype>
| eval RunningLessThanRequired = if(CountRunning < CountRequired, 1, 0)
| where RunningLessThanRequired = 1

View solution in original post

rajs115
Path Finder

Thanks Jamie. It worked

0 Karma

jamie00171
Communicator

Hi @rajs115 

 

Does something like this work for you:

 

index=<your index> sourcetype=<your sourcetype>
| eval RunningLessThanRequired = if(CountRunning < CountRequired, 1, 0)
| where RunningLessThanRequired = 1
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...