You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Splunk中构建多事件对比以保留RFM周期最大duration事件?

筛选Splunk中RFM模式时长周期的峰值拐点事件

我用Splunk的transaction命令统计设备处于RFM(reduced_functionality_mode)模式的时长,但结果里duration字段存在大量冗余数据。原本只想统计RFM模式为"yes"时段的总时长,但现在需要保留每个duration递增周期的峰值拐点事件——也就是当后续事件的duration小于当前事件时,保留当前事件。

现有查询语句:

index=crowdstrike sourcetype=crowdstrike:device:json 
| transaction falcon_device.hostname startswith="falcon_device.reduced_functionality_mode=yes" endswith="falcon_device.reduced_functionality_mode=no"
| table  _time duration

示例数据:

_timeduration
2022-10-28 06:07:45888198
2022-10-28 05:33:44892400
2022-10-28 04:57:44896360
2022-08-22 18:25:533862
2022-08-22 18:01:537703
2022-08-22 17:35:5311543

如示例所示,duration会在达到峰值后重置并重新递增,需要保留每个周期的峰值事件。


可以用streamstats命令获取下一个事件的duration值,再通过条件筛选出符合要求的拐点事件。完整查询如下:

index=crowdstrike sourcetype=crowdstrike:device:json 
| transaction falcon_device.hostname startswith="falcon_device.reduced_functionality_mode=yes" endswith="falcon_device.reduced_functionality_mode=no"
| sort 0 _time  // 按时间正序排列,保证事件顺序正确
| streamstats current=f window=1 last(duration) as next_duration  // 获取下一个事件的duration值
| where isnull(next_duration) OR duration > next_duration  // 保留最后一个事件,或当前duration大于下一个的峰值事件
| table _time duration

各部分说明:

  • sort 0 _time:按时间正序排列所有事件,确保streamstats能正确关联前后事件,0表示不限制结果数量。
  • streamstats current=f window=1 last(duration) as next_duration:current=f表示不包含当前事件,window=1仅取下一个事件的duration,并命名为next_duration。
  • where isnull(next_duration) OR duration > next_duration:筛选逻辑,要么是序列最后一个事件(无后续事件,next_duration为空),要么当前事件的duration大于下一个事件——这就是每个周期的峰值拐点。

内容的提问来源于stack exchange,提问作者berensn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 20:05:39