Splunk Search

grouping similar field values

atreece
Path Finder

I have a set of events that are generated with locations in the form of xloc and yloc. (z, or height, is irrelevant) I am trying to find events that happen in the same place, but I want to group any events that happen in the same area, say 5 meters. (+-5)
Is there a way to do this in splunk?

Tags (1)
0 Karma
1 Solution

Ayn
Legend

You could probably use bucket for this. bucket puts continuous numerical values into discrete sets, so you could group together all xloc/yloc points within the same general area. Using this, if you'd want to get a count of the events within a certain range, you could do something like:

... | bucket xloc span=10 | bucket yloc span=10 | stats count by xloc,yloc

More information on the bucket command: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Bucket

View solution in original post

Ayn
Legend

You could probably use bucket for this. bucket puts continuous numerical values into discrete sets, so you could group together all xloc/yloc points within the same general area. Using this, if you'd want to get a count of the events within a certain range, you could do something like:

... | bucket xloc span=10 | bucket yloc span=10 | stats count by xloc,yloc

More information on the bucket command: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Bucket

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...