<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do you subtract two column values in Splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-subtract-two-column-values-in-Splunk/m-p/400277#M167415</link>
    <description>&lt;P&gt;Hi team,&lt;/P&gt;

&lt;P&gt;say i have a column like this :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;_time    A
11pm  30
10pm  40
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have to subtract 40-30 and store in a new field &lt;/P&gt;

&lt;P&gt;How do I achieve this?&lt;/P&gt;</description>
    <pubDate>Wed, 26 Sep 2018 09:43:14 GMT</pubDate>
    <dc:creator>Mohsin123</dc:creator>
    <dc:date>2018-09-26T09:43:14Z</dc:date>
    <item>
      <title>How do you subtract two column values in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-subtract-two-column-values-in-Splunk/m-p/400277#M167415</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;

&lt;P&gt;say i have a column like this :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;_time    A
11pm  30
10pm  40
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have to subtract 40-30 and store in a new field &lt;/P&gt;

&lt;P&gt;How do I achieve this?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 09:43:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-subtract-two-column-values-in-Splunk/m-p/400277#M167415</guid>
      <dc:creator>Mohsin123</dc:creator>
      <dc:date>2018-09-26T09:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do you subtract two column values in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-subtract-two-column-values-in-Splunk/m-p/400278#M167416</link>
      <description>&lt;P&gt;hi @Mohsin123&lt;/P&gt;

&lt;P&gt;try this &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|makeresults |eval A=30 |append [|makeresults |eval A=40] |delta A
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If it is helped you pls accept as answer or up vote it&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 09:50:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-subtract-two-column-values-in-Splunk/m-p/400278#M167416</guid>
      <dc:creator>harishalipaka</dc:creator>
      <dc:date>2018-09-26T09:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: How do you subtract two column values in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-subtract-two-column-values-in-Splunk/m-p/400279#M167417</link>
      <description>&lt;P&gt;thanks but what if i have to do this with n coloumns , its row 2 value - the row 1 value&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 09:55:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-subtract-two-column-values-in-Splunk/m-p/400279#M167417</guid>
      <dc:creator>Mohsin123</dc:creator>
      <dc:date>2018-09-26T09:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: How do you subtract two column values in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-subtract-two-column-values-in-Splunk/m-p/400280#M167418</link>
      <description>&lt;P&gt;Splunk active/inactive users&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;input type="radio" token="active_account"&amp;gt;
  &amp;lt;label&amp;gt;Active accounts&amp;lt;/label&amp;gt;
  &amp;lt;choice value="*"&amp;gt;all&amp;lt;/choice&amp;gt;
  &amp;lt;choice value="1"&amp;gt;active&amp;lt;/choice&amp;gt;
  &amp;lt;choice value="0"&amp;gt;inactive&amp;lt;/choice&amp;gt;
  &amp;lt;default&amp;gt;1&amp;lt;/default&amp;gt;
&amp;lt;/input&amp;gt;
&amp;lt;input type="text" token="user_field" searchWhenChanged="true"&amp;gt;
  &amp;lt;label&amp;gt;User:&amp;lt;/label&amp;gt;
  &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;/input&amp;gt;
&amp;lt;input type="text" token="role_field" searchWhenChanged="true"&amp;gt;
  &amp;lt;label&amp;gt;Role:&amp;lt;/label&amp;gt;
  &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;/input&amp;gt;


&amp;lt;panel&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;| rest /services/authentication/users   | dedup title   | rename title as user | eval firstHit=0  | eval lastHit=0 | eval active=1 | table user, firstHit, lastHit, roles, active  | inputlookup append=true splunk_users | eval user=if(isnull(_key), user, _key)  | stats max(firstHit) as firstHit, max(lastHit) as lastHit, values(roles) as roles, max(active) as active by user | convert timeformat="%Y-%m-%d %H:%M:%S" ctime(firstHit) | convert timeformat="%Y-%m-%d %H:%M:%S" ctime(lastHit)  | eval active=if(active==1, active, 0) | search user="$user_field$" | search active=$active_account$ | search roles="$role_field$"&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-15m@m&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="count"&amp;gt;100&amp;lt;/option&amp;gt;
  &amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;User/Role/Index Management&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
  &amp;lt;title&amp;gt;Splunk indexes with corresponding roles&amp;lt;/title&amp;gt;
  &amp;lt;input type="radio" token="view_field1" searchWhenChanged="true"&amp;gt;
    &amp;lt;label&amp;gt;View:&amp;lt;/label&amp;gt;
    &amp;lt;choice value="| nomv index"&amp;gt;One line&amp;lt;/choice&amp;gt;
    &amp;lt;choice value=""&amp;gt;Human readable (currently not working)&amp;lt;/choice&amp;gt;
    &amp;lt;default&amp;gt;| nomv index&amp;lt;/default&amp;gt;
  &amp;lt;/input&amp;gt;
  &amp;lt;input type="text" token="role_field1" searchWhenChanged="true"&amp;gt;
    &amp;lt;label&amp;gt;Role:&amp;lt;/label&amp;gt;
    &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
  &amp;lt;/input&amp;gt;
  &amp;lt;input type="text" token="index_field1"&amp;gt;
    &amp;lt;label&amp;gt;Index:&amp;lt;/label&amp;gt;
    &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
  &amp;lt;/input&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;| inputlookup  admin_role_indexes 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;| eval index = mvappend(srchIndexesAllowed, imported_srchIndexesAllowed) | fields role, index  $view_field1$ | search role=$role_field1$ | search index=$index_field1$&lt;BR /&gt;
| dedup role&lt;BR /&gt;
| rex field=index max_match=200 "(?&amp;lt;idx&amp;gt;\w+)"&lt;BR /&gt;
| lookup admin_indexes_data_owners index as idx&lt;BR /&gt;
| stats values(index) as index, values(data_owner) as data_owner by role&lt;BR /&gt;
          &lt;EARLIEST&gt;-15m@m&lt;/EARLIEST&gt;&lt;BR /&gt;
          &lt;LATEST&gt;now&lt;/LATEST&gt;&lt;BR /&gt;
        &lt;BR /&gt;
        20&lt;BR /&gt;
        none&lt;BR /&gt;
        none&lt;BR /&gt;
        false&lt;BR /&gt;
        true&lt;BR /&gt;
      &lt;BR /&gt;
    &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
  &amp;lt;title&amp;gt;Splunk users details&amp;lt;/title&amp;gt;
  &amp;lt;input type="radio" token="view_field2" searchWhenChanged="true"&amp;gt;
    &amp;lt;label&amp;gt;View:&amp;lt;/label&amp;gt;
    &amp;lt;choice value="| nomv index | nomv role"&amp;gt;One line&amp;lt;/choice&amp;gt;
    &amp;lt;choice value=""&amp;gt;Human readable (currently not working)&amp;lt;/choice&amp;gt;
    &amp;lt;default&amp;gt;| nomv index | nomv role&amp;lt;/default&amp;gt;
  &amp;lt;/input&amp;gt;
  &amp;lt;input type="text" token="user_field2" searchWhenChanged="true"&amp;gt;
    &amp;lt;label&amp;gt;User:&amp;lt;/label&amp;gt;
    &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
  &amp;lt;/input&amp;gt;
  &amp;lt;input type="text" token="role_field2" searchWhenChanged="true"&amp;gt;
    &amp;lt;label&amp;gt;Role:&amp;lt;/label&amp;gt;
    &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
  &amp;lt;/input&amp;gt;
  &amp;lt;input type="text" token="index_field2"&amp;gt;
    &amp;lt;label&amp;gt;Index:&amp;lt;/label&amp;gt;
    &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
  &amp;lt;/input&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;| inputlookup admin_user_index_role | rename roles as role  $view_field2$ | search user=$user_field2$ | search role=$role_field2$ | search index=$index_field2$ | lookup splunk_users _key as user OUTPUT lastHit as last_seen| eval user=if(isnull(_key), user, _key) | convert timeformat="%Y-%m-%d %H:%M:%S" ctime(last_seen) | table user, last_seen, index, role | eval last_seen=if(isnull(last_seen), "never", last_seen)&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;-15m@m&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
  &amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:00:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-subtract-two-column-values-in-Splunk/m-p/400280#M167418</guid>
      <dc:creator>ritchierich</dc:creator>
      <dc:date>2020-09-30T04:00:26Z</dc:date>
    </item>
  </channel>
</rss>

