Splunk Search

Predict: Can I show only the predicted events in the future?

mkelderm
Path Finder

I like the predict clause, but how can I show only the prediction of the 'future'. For example:

index=prd_stats earliest=-5d sourcetype=appman:DatabaseQueryMonitor resource=Counts@GMPROD_MONDRIAAN attribute=AANTAL |  timechart useother=f usenull=f span=15m limit=0 avg(value) as aantal | predict aantal lower99=low upper99=high algorithm=LLP future_timespan=40

This query shows the prediction for the comming 10 hours (span*40). But I only want to see the prediction of this 10 hours.

Tags (3)
0 Karma
1 Solution

guilmxm
SplunkTrust
SplunkTrust

Hi,

You can do it easily, append a "where" condition after the predict command to exclude non predicted data.

In you example, append:

| where isnull(aantal)

View solution in original post

guilmxm
SplunkTrust
SplunkTrust

Hi,

You can do it easily, append a "where" condition after the predict command to exclude non predicted data.

In you example, append:

| where isnull(aantal)

View solution in original post

mkelderm
Path Finder

so simple ! Thanks!

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.