Splunk Search

I would like to change to 10% deviation from standard for below query

paragg
Loves-to-Learn Lots
index="xyz" sourcetype = abc"
| search Country="ggg"  statusCode=200
| stats count as Registration
| where Registration =0



Could you please help me to modify this query. Time period is last 24 hours. 

Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Your requirement is unclear and imprecise - what is "standard"? what are you trying to establish the deviation of? your current search will only return results when there are no events, so you have no events to establish any deviation from standard anyway!

Please clarify

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...