Splunk Search

traverse through each record and check whether that ticket breached SLA or not

avi123
Explorer

Hi All,

I have one set of output having 8 closed tickets for two consecutive months as a result of splunk query. I also need to check whether each one of them breached SLAs or not based on their level of priority. How to traverse through each and every record through splunk query?

Please Note: I also need to put in the formula to check which tickets got breached and what is the breach age and finally average age for breach of tickets. Please suggest how to proceed with this use case. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It depends on what data you have in your events and how they are linked. For example, is the ticket number unique to the ticket. Do subsequent events contain all the information from previous events for the same ticket? Is the SLA fixed for all tickets or is there a way to determine that the SLA is from the ticket (via a lookup perhaps)? Please provide more detail, ideally some anonymised representative sample events so we can see what you are dealing with.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...