Splunk Search

Using delta with events that need to be grouped by another parameter

tomdee
New Member

I have events that contain a counter of a number of packets sent. Each event applies only to a single port.

How do I graph the rate of packets sent per port?

I've tried using delta, but I can't work out how to do that per port.

Tags (1)
0 Karma

justinfranks
Path Finder

delta is only really a comparison between 2 events.

Would something like this work?

| timechart packets by port
0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...