<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: time difference between two events. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/time-difference-between-two-events/m-p/95598#M182470</link>
    <description>&lt;P&gt;If you want to use transaction, create a transaction that starts with the first event and ends with the second. The &lt;CODE&gt;transaction&lt;/CODE&gt; command will automatically create a field &lt;CODE&gt;duration&lt;/CODE&gt; that holds the time different between the first and the last event in the transaction, so if you have Splunk configured to use "TIMESTAMP" as what it takes its own timestamp from, just getting the &lt;CODE&gt;duration&lt;/CODE&gt; field will give you what you want.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jul 2012 11:48:47 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2012-07-11T11:48:47Z</dc:date>
    <item>
      <title>time difference between two events.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-difference-between-two-events/m-p/95597#M182469</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I need to calucalte the time difference between two events in splunk..using the transaction command ....how can i do that ..??&lt;/P&gt;

&lt;P&gt;in my logs i have my own field called &lt;STRONG&gt;"TIMESTAMP"&lt;/STRONG&gt; . Please help..&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2012 10:24:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-difference-between-two-events/m-p/95597#M182469</guid>
      <dc:creator>rakesh_498115</dc:creator>
      <dc:date>2012-07-11T10:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: time difference between two events.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/time-difference-between-two-events/m-p/95598#M182470</link>
      <description>&lt;P&gt;If you want to use transaction, create a transaction that starts with the first event and ends with the second. The &lt;CODE&gt;transaction&lt;/CODE&gt; command will automatically create a field &lt;CODE&gt;duration&lt;/CODE&gt; that holds the time different between the first and the last event in the transaction, so if you have Splunk configured to use "TIMESTAMP" as what it takes its own timestamp from, just getting the &lt;CODE&gt;duration&lt;/CODE&gt; field will give you what you want.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2012 11:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/time-difference-between-two-events/m-p/95598#M182470</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-07-11T11:48:47Z</dc:date>
    </item>
  </channel>
</rss>

