Splunk Search

Combine Values into one event then search if one of the values are contained

geraldcontreras
Path Finder

Hi,
Thanks in advance

This is hard one to put well in the title

Basically i have sets of data which contain Students Scores for tests. Students can take these tests multiple times.
I need a search that will show only events where the student has never scroed greater than 80

Sample Data (fields "Display_Name" and "result":

Display_Name result
John_Doe 20
John_Doe 60
John_Doe 80
Jane_Doe 95
Jack_Doe 20

Results i need (as he is the only person not to have scored 80 or higher:
Jack_Doe

i cant just simply use
"where result < 80"
because then John_doe will be included.

I need something that will exclude someone who has scored 80 or higher.

I have tried all matter of combinations, which i wont list as i find sometimes its best for people to approach without prior conception.

Thanks you all

0 Karma
1 Solution

geraldcontreras
Path Finder

I found the answer by using max
it was staring me in the face the whole time

| stats max(Score) as result by Display_Name | where result < 80

must of been a Friday! 😄

View solution in original post

0 Karma

geraldcontreras
Path Finder

I found the answer by using max
it was staring me in the face the whole time

| stats max(Score) as result by Display_Name | where result < 80

must of been a Friday! 😄

0 Karma

renjith_nair
Legend

@geraldcontreras , converted your comment to answer. You may accept it as answer and close the thread 🙂

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...