<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Column value differences in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Column-value-differences/m-p/291033#M175054</link>
    <description>&lt;P&gt;Hi, you can thy this:&lt;/P&gt;

&lt;P&gt;index=xpto source=abc | eval column2a = column2 - column1, column3a = column3 - column2 | table column2a, column3a&lt;/P&gt;</description>
    <pubDate>Wed, 22 Mar 2017 14:25:52 GMT</pubDate>
    <dc:creator>maffreitas</dc:creator>
    <dc:date>2017-03-22T14:25:52Z</dc:date>
    <item>
      <title>Column value differences</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-value-differences/m-p/291032#M175053</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;

&lt;P&gt;I have columns  like column1, coulmn2, column3... and I want output as column1, column2=column2-column1, column3=column3-column2, col4=col4-col3...&lt;/P&gt;

&lt;P&gt;Is there any way to write search query for this?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 11:50:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-value-differences/m-p/291032#M175053</guid>
      <dc:creator>Chinmai</dc:creator>
      <dc:date>2017-03-22T11:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Column value differences</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-value-differences/m-p/291033#M175054</link>
      <description>&lt;P&gt;Hi, you can thy this:&lt;/P&gt;

&lt;P&gt;index=xpto source=abc | eval column2a = column2 - column1, column3a = column3 - column2 | table column2a, column3a&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 14:25:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-value-differences/m-p/291033#M175054</guid>
      <dc:creator>maffreitas</dc:creator>
      <dc:date>2017-03-22T14:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Column value differences</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-value-differences/m-p/291034#M175055</link>
      <description>&lt;P&gt;use the eval command / function &lt;BR /&gt;
... | eval newColumn = columnX - columnY&lt;BR /&gt;
more on this topic here:  &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 14:59:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-value-differences/m-p/291034#M175055</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-03-22T14:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: Column value differences</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-value-differences/m-p/291035#M175056</link>
      <description>&lt;P&gt;How many rows do you get? Do you have other columns as well other than columnNs where N=1,2,3...?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 15:25:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-value-differences/m-p/291035#M175056</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-03-22T15:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Column value differences</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Column-value-differences/m-p/291036#M175057</link>
      <description>&lt;P&gt;Hello All, &lt;/P&gt;

&lt;P&gt;Thanks for your answers, but the columns number is more. I cannot do colY=colY-colX every time,  is there any better solution?&lt;/P&gt;

&lt;P&gt;I have around 20-30 rows as output and other than columns col1,col2,col3.. I have another one column which  I am using in my by clause of search query&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 07:09:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Column-value-differences/m-p/291036#M175057</guid>
      <dc:creator>Chinmai</dc:creator>
      <dc:date>2017-03-23T07:09:38Z</dc:date>
    </item>
  </channel>
</rss>

