Splunk Search

Splunk search

Emily12
Explorer

Hi Everyone,

How can I write splunk search query to check if for particular variable value has increased in 4 hours.

Thanks in advance 😊

Labels (1)
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Emily12,

your request is just a little vague!

Anyway, try someting like this:

your_search earliest=-4h@h latest=now
| stats min(variable) AS min max(variable) AS max 
| where NOT min=max

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Emily12,

your request is just a little vague!

Anyway, try someting like this:

your_search earliest=-4h@h latest=now
| stats min(variable) AS min max(variable) AS max 
| where NOT min=max

Ciao.

Giuseppe

Emily12
Explorer

@gcusello Thank you so much.

This is what I was looking for.

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Emily12,

good for you.

Ciao and happy splunking.

Giuseppe

P.S. Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...