Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Is there any way to get the top 10 hosts with event count spike compared to Yesterday's event count in splunk from a lookup which contains hosts?

$
0
0
I have lookup file which contains a list of hosts around 500 as follows host A B C d Now, how to write a query to identify the top 10 hosts with event count spike compared to yesterday's event count ? Probably like below or any better way of presenting this would be helpfull. host Yesterday Today D 2.2 GB 8 GB H 1.1 GB 3 GB Y 0.5 GB 1.4 GB

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>