Splunk Search

eval duration/latency

Mohsin123
Path Finder

My timestamp-in and timestamp-out fields are in this format 2018-07-23T15:53:11.588Z
how do i calculate duration ?
i am calculating latency in time i.e response code .

i tried |eval tin=substr(tostring(timestamp-in),12,23) and also strptime

Anyone can help ?

Tags (3)
0 Karma

somesoni2
Revered Legend

Try like this

your current search | eval latency=strptime('timestamp-out',"%Y-%m-%dT%H:%M:%S.%3N%Z")-strptime('timestamp-in',"%Y-%m-%dT%H:%M:%S.%3N%Z")
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...