Splunk Search
Highlighted

Using delta with events that need to be grouped by another parameter

New Member

I have events that contain a counter of a number of packets sent. Each event applies only to a single port.

How do I graph the rate of packets sent per port?

I've tried using delta, but I can't work out how to do that per port.

Tags (1)
0 Karma
Highlighted

Re: Using delta with events that need to be grouped by another parameter

Path Finder

delta is only really a comparison between 2 events.

Would something like this work?

| timechart packets by port
0 Karma