Splunk Search

I would like to change to 10% deviation from standard for below query

paragg
Loves-to-Learn Lots
index="xyz" sourcetype = abc"
| search Country="ggg"  statusCode=200
| stats count as Registration
| where Registration =0



Could you please help me to modify this query. Time period is last 24 hours. 

Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Your requirement is unclear and imprecise - what is "standard"? what are you trying to establish the deviation of? your current search will only return results when there are no events, so you have no events to establish any deviation from standard anyway!

Please clarify

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...