Splunk Search

I am trying to create a report for displaying number of times, replacement of printer supply unit in 1 year, by calculating when the supply level is zero, by IP. Is there any one to help on this?

sabithanitg
New Member

create a report for displaying number of times, replacement of printer supply unit in 1 year, by calculating when the supply level is zero, and by IP.

Tags (1)
0 Karma
1 Solution

aweitzman
Motivator

Without knowing what your data looks like, this suggestion will make some obvious assumptions about your events:

source=printersupplyunits | stats count(eval(supplylevel=0)) as count by IP

Where printersupplyunits is the source of your events, IP is the IP address of each event, and supplylevel represents the supply level at the time of the event.

View solution in original post

0 Karma

aweitzman
Motivator

Without knowing what your data looks like, this suggestion will make some obvious assumptions about your events:

source=printersupplyunits | stats count(eval(supplylevel=0)) as count by IP

Where printersupplyunits is the source of your events, IP is the IP address of each event, and supplylevel represents the supply level at the time of the event.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...