Splunk Search

I would like to change to 10% deviation from standard for below query

paragg
Loves-to-Learn Lots
index="xyz" sourcetype = abc"
| search Country="ggg"  statusCode=200
| stats count as Registration
| where Registration =0



Could you please help me to modify this query. Time period is last 24 hours. 

Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Your requirement is unclear and imprecise - what is "standard"? what are you trying to establish the deviation of? your current search will only return results when there are no events, so you have no events to establish any deviation from standard anyway!

Please clarify

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...