Splunk Search

how to search event occurrence in the span of 0 to 2 seconds and 2 to 5 seconds and above 10 seconds

john_q
Explorer

i have a data which consists of multiple exceptions . so i have to figure out how many exceptions are occurred like 0 to 2 seconds and 2 to 5 seconds and 5 to 10 seconds timerenge in the span of last 24 hours. can you please tell me the search query . thanks in advance

i want to show output like:

ExcepitonsCount_0to2sec ExcepitonsCount_2to5sec ExcepitonsCount_5to10sec ExcepitonsCount_above10sec
101 102 103 104

Tags (1)
0 Karma
1 Solution

renjith_nair
Legend

Hi @john_q,

Does this work for you ?

"your search to filter exceptions"|timechart span=1s count|streamstats count as sec
|stats sum(eval(if(sec<3,count,null()))) as ExcepitonsCount_0to2sec ,sum(eval(if(sec>2 AND sec<6,count,null()))) as ExcepitonsCount_2to5sec ,sum(eval(if(sec>5 AND sec<11,count,null()))) as ExcepitonsCount_5to10sec ,sum(eval(if(sec>10,count,null()))) as ExcepitonsCount_above10sec
---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

Hi @john_q,

Does this work for you ?

"your search to filter exceptions"|timechart span=1s count|streamstats count as sec
|stats sum(eval(if(sec<3,count,null()))) as ExcepitonsCount_0to2sec ,sum(eval(if(sec>2 AND sec<6,count,null()))) as ExcepitonsCount_2to5sec ,sum(eval(if(sec>5 AND sec<11,count,null()))) as ExcepitonsCount_5to10sec ,sum(eval(if(sec>10,count,null()))) as ExcepitonsCount_above10sec
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...