Splunk Search

how can I get an aggregation like max() for multiple happenings over a diffenrent periods?

GDude
New Member

My results are in the following table:
happening time_duration Aufnahme zaehler_anzahl

1 50.405 Tasche4 685
2 48.414 Tasche3 629
3 63.486 Tasche2 700
4 50.392 Tasche1 618
5 49.405 Tasche5 689
6 49.348 Tasche4 614
7 52.479 Tasche3 694
8 49.379 Tasche2 647
9 51.425 Tasche1 687
10 50.437 Tasche5 638
11 51.516 Tasche4 675
12 62.422 Tasche3 681
13 54.421 Tasche2 682
Now I have the problem to get key-values for every happening followed by an amount of zaehler_anzahl. The curve in this period you will see in the following Picture.
alt text
At the end I want to habe all these periods separate to do further analyses.
Thanks in advance for your help.
George

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...