Splunk Search

I would like to change to 10% deviation from standard for below query

paragg
Loves-to-Learn Lots
index="xyz" sourcetype = abc"
| search Country="ggg"  statusCode=200
| stats count as Registration
| where Registration =0



Could you please help me to modify this query. Time period is last 24 hours. 

Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Your requirement is unclear and imprecise - what is "standard"? what are you trying to establish the deviation of? your current search will only return results when there are no events, so you have no events to establish any deviation from standard anyway!

Please clarify

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...