Splunk Search

grouping similar field values

atreece
Path Finder

I have a set of events that are generated with locations in the form of xloc and yloc. (z, or height, is irrelevant) I am trying to find events that happen in the same place, but I want to group any events that happen in the same area, say 5 meters. (+-5)
Is there a way to do this in splunk?

Tags (1)
0 Karma
1 Solution

Ayn
Legend

You could probably use bucket for this. bucket puts continuous numerical values into discrete sets, so you could group together all xloc/yloc points within the same general area. Using this, if you'd want to get a count of the events within a certain range, you could do something like:

... | bucket xloc span=10 | bucket yloc span=10 | stats count by xloc,yloc

More information on the bucket command: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Bucket

View solution in original post

Ayn
Legend

You could probably use bucket for this. bucket puts continuous numerical values into discrete sets, so you could group together all xloc/yloc points within the same general area. Using this, if you'd want to get a count of the events within a certain range, you could do something like:

... | bucket xloc span=10 | bucket yloc span=10 | stats count by xloc,yloc

More information on the bucket command: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Bucket

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...