Hi Everyone,
How can I write splunk search query to check if for particular variable value has increased in 4 hours.
Thanks in advance 😊
Hi @Emily12,
your request is just a little vague!
Anyway, try someting like this:
your_search earliest=-4h@h latest=now
| stats min(variable) AS min max(variable) AS max
| where NOT min=max
Ciao.
Giuseppe
Hi @Emily12,
your request is just a little vague!
Anyway, try someting like this:
your_search earliest=-4h@h latest=now
| stats min(variable) AS min max(variable) AS max
| where NOT min=max
Ciao.
Giuseppe