I want to check for how long my field TPP_ID is empty. I want to check date and time. Is it possible using splunk query?
Try this:
index=<index_name> NOT TPP_ID=* | stats earliest(_time) as et latest(_time) as lt | eval time_diff = lt - et
Try this:
index=<index_name> NOT TPP_ID=* | stats earliest(_time) as et latest(_time) as lt | eval time_diff = lt - et