如何在Splunk中构建多事件对比以保留RFM周期最大duration事件?
筛选Splunk中RFM模式时长周期的峰值拐点事件
我用Splunk的transaction命令统计设备处于RFM(reduced_functionality_mode)模式的时长,但结果里duration字段存在大量冗余数据。原本只想统计RFM模式为"yes"时段的总时长,但现在需要保留每个duration递增周期的峰值拐点事件——也就是当后续事件的duration小于当前事件时,保留当前事件。
现有查询语句:
index=crowdstrike sourcetype=crowdstrike:device:json | transaction falcon_device.hostname startswith="falcon_device.reduced_functionality_mode=yes" endswith="falcon_device.reduced_functionality_mode=no" | table _time duration
示例数据:
| _time | duration |
|---|---|
| 2022-10-28 06:07:45 | 888198 |
| 2022-10-28 05:33:44 | 892400 |
| 2022-10-28 04:57:44 | 896360 |
| 2022-08-22 18:25:53 | 3862 |
| 2022-08-22 18:01:53 | 7703 |
| 2022-08-22 17:35:53 | 11543 |
如示例所示,duration会在达到峰值后重置并重新递增,需要保留每个周期的峰值事件。
可以用streamstats命令获取下一个事件的duration值,再通过条件筛选出符合要求的拐点事件。完整查询如下:
index=crowdstrike sourcetype=crowdstrike:device:json | transaction falcon_device.hostname startswith="falcon_device.reduced_functionality_mode=yes" endswith="falcon_device.reduced_functionality_mode=no" | sort 0 _time // 按时间正序排列,保证事件顺序正确 | streamstats current=f window=1 last(duration) as next_duration // 获取下一个事件的duration值 | where isnull(next_duration) OR duration > next_duration // 保留最后一个事件,或当前duration大于下一个的峰值事件 | table _time duration
各部分说明:
sort 0 _time:按时间正序排列所有事件,确保streamstats能正确关联前后事件,0表示不限制结果数量。streamstats current=f window=1 last(duration) as next_duration:current=f表示不包含当前事件,window=1仅取下一个事件的duration,并命名为next_duration。where isnull(next_duration) OR duration > next_duration:筛选逻辑,要么是序列最后一个事件(无后续事件,next_duration为空),要么当前事件的duration大于下一个事件——这就是每个周期的峰值拐点。
内容的提问来源于stack exchange,提问作者berensn
相关产品推荐
相关产品推荐

