Splunk Search

Remove top from results

rhum_defintel
New Member

I want to remove the top results from my final results. Essentially, removing outliers.

Tags (2)
0 Karma

altink
Builder

Hello

is there any development on this ?

remove top x rows from result

best regards
Altin

0 Karma

devin_stonecyph
Explorer

landen99
Motivator

search | sort -field1 | head 20

0 Karma

yannK
Splunk Employee
Splunk Employee

if you want to filter the highest values, you can use a where condition, or an eval to normalize it.

example :

sourcetype=mysourcetype | where myfield < 100 | timechart max(myfield) by host

sourcetype=mysourcetype | eval myfield=if(myfield<100,myfield,0) | timechart max(myfield) by host

0 Karma

landen99
Motivator

grabs bottom 20 results

0 Karma

rhum_defintel
New Member

I want to remove the results that are listed in top.

0 Karma

Ayn
Legend

For getting the most common values there's top (http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Top ).

For getting the most rare values, rare (http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Rare ).

There's also a number of statistical functions available that might be suitable for you to use: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonStatsFunctions

0 Karma

rhum_defintel
New Member

I have a timechart that has spikes of data. I would like to remove those spikes so I can calculate an average.

0 Karma

Ayn
Legend

Give more details on what you want to achieve, preferrably with some sample events so we know more about how to solve the problem.

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out &gt;&gt; As our brave ...