Splunk Search

Substract actual field with previous event field

lpolo
Motivator

I have the following summary index

_time               Type        Number
11/14/11 3:00:53.000 PM     New     56802
11/14/11 2:00:44.000 PM     New     56581
11/14/11 1:01:00.000 PM     New     56459
11/14/11 12:00:51.000 PM    New     56327
11/14/11 11:00:42.000 AM    New     56187
11/14/11 10:00:58.000 AM    New     55998
11/14/11 9:01:08.000 AM     New     55724
11/14/11 8:01:12.000 AM     New     55282

I have been not able to find a query that substract the last event "Number" with the previous one. For example

Events:

_time               Type        Number
11/14/11 3:00:53.000 PM     New     56802
11/14/11 2:00:44.000 PM     New     56581

New Number = 56802 - 56581

Result set:

New Number = 301

Thanks,

Tags (2)
1 Solution

Ayn
Legend

Ayn
Legend

This is precisely what you could use the delta command for.

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Delta

Ayn
Legend

No problem. Could you please mark my answer as accepted? Thanks!

0 Karma

lpolo
Motivator

Thanks for your help

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...