Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How can I filter my results to compare values in two fields?

$
0
0
I have 2 fields called **sc_bytes** & **cs_bytes** in my results. How can I then filter my results to give me events when the value for **cs_bytes** is *greater* than the value for **sc_bytes**? Much thanks.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>