Splunk Search

Substract actual field with previous event field

lpolo
Motivator

I have the following summary index

_time               Type        Number
11/14/11 3:00:53.000 PM     New     56802
11/14/11 2:00:44.000 PM     New     56581
11/14/11 1:01:00.000 PM     New     56459
11/14/11 12:00:51.000 PM    New     56327
11/14/11 11:00:42.000 AM    New     56187
11/14/11 10:00:58.000 AM    New     55998
11/14/11 9:01:08.000 AM     New     55724
11/14/11 8:01:12.000 AM     New     55282

I have been not able to find a query that substract the last event "Number" with the previous one. For example

Events:

_time               Type        Number
11/14/11 3:00:53.000 PM     New     56802
11/14/11 2:00:44.000 PM     New     56581

New Number = 56802 - 56581

Result set:

New Number = 301

Thanks,

Tags (2)
1 Solution

Ayn
Legend

Ayn
Legend

This is precisely what you could use the delta command for.

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Delta

Ayn
Legend

No problem. Could you please mark my answer as accepted? Thanks!

0 Karma

lpolo
Motivator

Thanks for your help

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...