Splunk Search

I want number of days between two events in splunk search?

uagraw01
Builder

My query

index=main source=secure.log sourcetype=*
| stats earliest(_time) as start, latest(_time) as stop
| eval start=strftime(start, "%m/%d/%y") | eval stop=strftime(stop, "%m/%d/%y") | eval days = round((start-stop)/86400). Please refer my below result.

start stop
11/16/18 11/23/18

Here i can see start and stop date but want to find difference between start and stop so i can found number of days gap between them. So in above result i wants days column and difference is 7 days. But days column is not coming here. Please suggest.

Tags (1)
0 Karma

493669
Super Champion

try below-

| eval start = strptime(start , "%m/%d/%y")| eval stop = strptime(stop, "%m/%d/%y")| eval days= round((stop-start)/86400)
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...