Splunk Search

How to compare search result for first 15 min and last 45 min?

salavilli0611
New Member

Following is the result we got

   Action_ Name Time    Count
ABC        1:15 AM      100
ABC        1:30 AM      200
ABC           1:45 AM       300
ABC             2:00        50

Now I want to compare the row2 (1:30 AM) Count : 200 with row4(2:00 AM) Count 50
I am new to splunk and I don't know how to do it

Following is the below splunk query:

index=... sourcetype= .... | bucket _time span=15m | stats count by Action_Name,_time
Tags (2)
0 Karma

jacobpevans
Motivator

Greetings @salavilli0611,

Please take a look at this run-anywhere search. If needed, you can add a by to the timechart, but your sample data does not indicate you do. When you plug this into your search, replace count with sum(count) (and remove the bin command since timechart does that for you)

index=_internal sourcetype=splunkd log_level=ERROR
| timechart span=15m count
| timewrap 15min

alt text

Cheers,
Jacob

If you feel this response answered your question, please do not forget to mark it as such. If it did not, but you do have the answer, feel free to answer your own post and accept that as the answer.
0 Karma

adonio
Ultra Champion

what will be the desired result / view / table look like?

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...