Hello,
what must I do to report only values of diff_min greater than e.g. 1
endTime startTime
| eval ET=strptime(endTime,"%Y-%m-%d %H:%M:%S.%3Q")
| eval ST=strptime(startTime,"%Y-%m-%d %H:%M:%S.%3Q")
| eval diff_min=(ET-ST)/60
| fields diff_min startTime endTime
| sort -diff_min
Sorry, it's my first dashboard.
Thank you 🙂
Steff
Hi @SteffHH.,
if this answer solves your needs, please, accept it or tell me how I can help you.
Ciao and happy splunking.
Giuseppe
P.S.: Karma Points are appreciated 😉
Hi @SteffHH,
I think that you could try the Splunk Search Tutorial, To understand how to build a search https://docs.splunk.com/Documentation/Splunk/8.0.6/SearchTutorial/WelcometotheSearchTutorial
Anyway, you have to:
having something like this:
index=your_index (action=start or action=end)
| stats earliest(_time) AS startTime latest(_time) AS endTime BY user
| eval
diff_min=(endTime-startTime)/60,
startTime=strftime(startTime,"%Y-%m-%d %H:%M:%S.%3Q"),
endTime=strftime(endTime,"%Y-%m-%d %H:%M:%S.%3Q")
| table user diff_min startTime endTime
| sort -diff_min
Ciao.
Giuseppe
Thx @gcusello for your help 😃
Hi @SteffHH.,
if this answer solves your needs, please, accept it or tell me how I can help you.
Ciao and happy splunking.
Giuseppe
P.S.: Karma Points are appreciated 😉