Splunk Search

Need help top 2 division


Hello I am a newbie on Splunk. I need to create an alert if #1 IP generated >2X of the #2 IP
and this is my search

sourcetype=csv | top sipAddress | head 2

sipAddress count 200 50

basically I will need to have first one divided by second if > 2 then I could put in my alert to send to customer.

Please help

0 Karma

Re: Need help top 2 division

Ultra Champion

Try something like this :

sourcetype=csv | top limit=2 sipAddress |streamstats first(count) as count_B window=1 global=f current=f | tail 1 |eval count_ratio=count_B/count | table count_ratio

View solution in original post