<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Subtract One Field from Another in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Subtract-One-Field-from-Another/m-p/469416#M192048</link>
    <description>&lt;P&gt;the problem is that after stats command you have only the fields the are in the stats, in your example you have only Field1Total, probably you have to use evenstats command or the values option of stats.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=index_name 
| eventstats count(Field2) as Field2Total
| eval Difference=Field2Total - Field1Total 
| table Difference
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=index_name 
| stats count(Field2) as Field2Total values(Field1) as Field1Total
| eval Difference=Field2Total - Field1Total 
| table Difference
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Sun, 09 Feb 2020 16:10:31 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-02-09T16:10:31Z</dc:date>
    <item>
      <title>Subtract One Field from Another</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Subtract-One-Field-from-Another/m-p/469415#M192047</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;

&lt;P&gt;I'm having trouble making a simple subtraction (well, I thought it would be simple!). Field1 is a number in string format, Field2 is a count of events. What am I doing wrong?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=index_name | convert num(Field1) as Field1Total | stats count(Field2) as Field2Total | eval Difference=Field2Total - Field1Total | table Difference
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks for your help! &lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 14:47:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Subtract-One-Field-from-Another/m-p/469415#M192047</guid>
      <dc:creator>driva</dc:creator>
      <dc:date>2020-02-09T14:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Subtract One Field from Another</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Subtract-One-Field-from-Another/m-p/469416#M192048</link>
      <description>&lt;P&gt;the problem is that after stats command you have only the fields the are in the stats, in your example you have only Field1Total, probably you have to use evenstats command or the values option of stats.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=index_name 
| eventstats count(Field2) as Field2Total
| eval Difference=Field2Total - Field1Total 
| table Difference
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=index_name 
| stats count(Field2) as Field2Total values(Field1) as Field1Total
| eval Difference=Field2Total - Field1Total 
| table Difference
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 16:10:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Subtract-One-Field-from-Another/m-p/469416#M192048</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-02-09T16:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Subtract One Field from Another</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Subtract-One-Field-from-Another/m-p/469417#M192049</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/SearchReference/Convert"&gt;Convert&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Automatically convert the fields to a number using the best conversion.&lt;BR /&gt;
&lt;CODE&gt;convert&lt;/CODE&gt;  use &lt;EM&gt;conversion&lt;/EM&gt;  .&lt;/P&gt;

&lt;P&gt;If you want to modify to number, simply &lt;CODE&gt;tonumber()&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 20:38:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Subtract-One-Field-from-Another/m-p/469417#M192049</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-02-09T20:38:34Z</dc:date>
    </item>
  </channel>
</rss>

