<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2 timestamp, the rest identical, how calculate duration ? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/2-timestamp-the-rest-identical-how-calculate-duration/m-p/452904#M128221</link>
    <description>&lt;PRE&gt;&lt;CODE&gt;tim:2019-01-18 10:27:54,id:bee236
tim:2019-01-18 10:38:07,id:bee236
tim:2019-01-21 09:27:09,id:thierry403
tim:2019-01-21 09:37:21,id:thierry403
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;cherry on the cake : the duration is near 10 min. So I will search bots who made a second try in time between 595 and 605secs.&lt;BR /&gt;
If tools on frequency could be more practical or efficient all solutions are welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
thx for your help&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2019 09:58:11 GMT</pubDate>
    <dc:creator>splunkLPN</dc:creator>
    <dc:date>2019-03-22T09:58:11Z</dc:date>
    <item>
      <title>2 timestamp, the rest identical, how calculate duration ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/2-timestamp-the-rest-identical-how-calculate-duration/m-p/452904#M128221</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;tim:2019-01-18 10:27:54,id:bee236
tim:2019-01-18 10:38:07,id:bee236
tim:2019-01-21 09:27:09,id:thierry403
tim:2019-01-21 09:37:21,id:thierry403
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;cherry on the cake : the duration is near 10 min. So I will search bots who made a second try in time between 595 and 605secs.&lt;BR /&gt;
If tools on frequency could be more practical or efficient all solutions are welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
thx for your help&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 09:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/2-timestamp-the-rest-identical-how-calculate-duration/m-p/452904#M128221</guid>
      <dc:creator>splunkLPN</dc:creator>
      <dc:date>2019-03-22T09:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: 2 timestamp, the rest identical, how calculate duration ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/2-timestamp-the-rest-identical-how-calculate-duration/m-p/452905#M128222</link>
      <description>&lt;P&gt;try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[your search|transaction id|eval dur_seconds=round((duration/1000),0)|table _time id dur_seconds
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 22 Mar 2019 10:24:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/2-timestamp-the-rest-identical-how-calculate-duration/m-p/452905#M128222</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-22T10:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: 2 timestamp, the rest identical, how calculate duration ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/2-timestamp-the-rest-identical-how-calculate-duration/m-p/452906#M128223</link>
      <description>&lt;P&gt;simple and efficient&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 11:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/2-timestamp-the-rest-identical-how-calculate-duration/m-p/452906#M128223</guid>
      <dc:creator>splunkLPN</dc:creator>
      <dc:date>2019-03-22T11:27:10Z</dc:date>
    </item>
  </channel>
</rss>

