Splunk Search

Substract actual field with previous event field

lpolo
Motivator

I have the following summary index

_time               Type        Number
11/14/11 3:00:53.000 PM     New     56802
11/14/11 2:00:44.000 PM     New     56581
11/14/11 1:01:00.000 PM     New     56459
11/14/11 12:00:51.000 PM    New     56327
11/14/11 11:00:42.000 AM    New     56187
11/14/11 10:00:58.000 AM    New     55998
11/14/11 9:01:08.000 AM     New     55724
11/14/11 8:01:12.000 AM     New     55282

I have been not able to find a query that substract the last event "Number" with the previous one. For example

Events:

_time               Type        Number
11/14/11 3:00:53.000 PM     New     56802
11/14/11 2:00:44.000 PM     New     56581

New Number = 56802 - 56581

Result set:

New Number = 301

Thanks,

Tags (2)
1 Solution

Ayn
Legend

Ayn
Legend

This is precisely what you could use the delta command for.

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Delta

Ayn
Legend

No problem. Could you please mark my answer as accepted? Thanks!

0 Karma

lpolo
Motivator

Thanks for your help

0 Karma
Get Updates on the Splunk Community!

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...

Stay Connected: Your Guide to February Tech Talks, Office Hours, and Webinars!

💌Keep the new year’s momentum going with our February lineup of Community Office Hours, Tech Talks, ...