Splunk Search

Using delta with events that need to be grouped by another parameter

tomdee
New Member

I have events that contain a counter of a number of packets sent. Each event applies only to a single port.

How do I graph the rate of packets sent per port?

I've tried using delta, but I can't work out how to do that per port.

Tags (1)
0 Karma

justinfranks
Path Finder

delta is only really a comparison between 2 events.

Would something like this work?

| timechart packets by port
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...