Splunk Search

I am trying to create a report for displaying number of times, replacement of printer supply unit in 1 year, by calculating when the supply level is zero, by IP. Is there any one to help on this?

sabithanitg
New Member

create a report for displaying number of times, replacement of printer supply unit in 1 year, by calculating when the supply level is zero, and by IP.

Tags (1)
0 Karma
1 Solution

aweitzman
Motivator

Without knowing what your data looks like, this suggestion will make some obvious assumptions about your events:

source=printersupplyunits | stats count(eval(supplylevel=0)) as count by IP

Where printersupplyunits is the source of your events, IP is the IP address of each event, and supplylevel represents the supply level at the time of the event.

View solution in original post

0 Karma

aweitzman
Motivator

Without knowing what your data looks like, this suggestion will make some obvious assumptions about your events:

source=printersupplyunits | stats count(eval(supplylevel=0)) as count by IP

Where printersupplyunits is the source of your events, IP is the IP address of each event, and supplylevel represents the supply level at the time of the event.

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...