You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何按ID从Splunk原始数据中提取180秒窗口内的PIN匹配次数

Splunk按180秒窗口统计各ID的PIN匹配次数

你可以通过提取ID字段、时间窗口分桶和分组统计来实现需求,具体查询语句如下:

index=transa "pin match" 
| rex "id (?<ID>[^\s]+)" 
| bin _time span=180s 
| stats count as Pincount by ID, _time

各部分说明:

  • index=transa "pin match":直接筛选交易索引中包含PIN匹配的事件,比用eval标记更高效
  • rex "id (?<ID>[^\s]+)":从原始日志中提取ID字段(匹配"id"后的非空白字符,适配你的UUID格式)
  • bin _time span=180s:将时间戳按180秒窗口分桶,把连续时间切割为一个个180秒的区间
  • stats count as Pincount by ID, _time:按每个ID和每个180秒窗口,统计该窗口内的PIN匹配次数

如果需要更直观的窗口时间展示,可以添加时间格式化语句:

index=transa "pin match" 
| rex "id (?<ID>[^\s]+)" 
| bin _time span=180s 
| eval window_start=strftime(_time, "%Y-%m-%d %H:%M:%S")
| stats count as Pincount by ID, window_start

内容的提问来源于stack exchange,提问作者John Newman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 17:01:15