Splunk Search

incremental value

DataOrg
Builder

I have sequence no of to populate . first column is the sequence of no and answers need to like in the second column

for Example
value value to populate
10 1
10 1
10 1
15 2
15 2
10 3

0 Karma
1 Solution

HiroshiSatoh
Champion

If increment is added for every NO ...

(your search)| streamstats sum(value)  by no

View solution in original post

HiroshiSatoh
Champion

If increment is added for every NO ...

(your search)| streamstats sum(value)  by no

DataOrg
Builder

its not sum.
we need to have a sequence of no if value are same we need to mark it as 1 . if current sequence changes to other set of no. we need to increase the value by 1

0 Karma

HiroshiSatoh
Champion

How's this?

 (your search)
|autoregress p=1 no as no_old
|eval change=if(no=no_old,0,1)
| streamstats sum(change) as inc_value
|table no inc_value
0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...