<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to find the _time difference in a list of eventTypes by algorithm (non-sequencial order)? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-time-difference-in-a-list-of-eventTypes-by/m-p/562328#M195572</link>
    <description>&lt;P&gt;Why isn't I I-G and L L-J and M M-L as these would seem to fit a pattern or are these completely arbitrary which would make optimising the search rather difficult?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Aug 2021 22:47:29 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-08-05T22:47:29Z</dc:date>
    <item>
      <title>How to find the _time difference in a list of eventTypes by algorithm (non-sequencial order)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-time-difference-in-a-list-of-eventTypes-by/m-p/562325#M195570</link>
      <description>&lt;P&gt;Hello Splunk Community&lt;/P&gt;
&lt;P&gt;I'm working on a SPL to give _time difference of list of eventTypes as per the algorithm. Currently I'm using the below query.&lt;/P&gt;
&lt;P&gt;index=apple source=datapipe AccountNumber=*&lt;/P&gt;
&lt;P&gt;eventType=newyork&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OR &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=california&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OR&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=boston&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OR &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=houston&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;OR &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=dallas&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; OR &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=austin&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; OR&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=Irvine&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; OR &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=Washington&amp;nbsp; &amp;nbsp; &amp;nbsp; OR &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=Atlanta&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;OR&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=San Antonio&amp;nbsp; &amp;nbsp; &amp;nbsp; OR &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=Brazil&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;OR&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=Mumbai&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; OR&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventType=Delhi&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; OR&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;|fieldformat _time=strftime(_time,"%m/%d/%Y%I:%M:%S %p")&lt;/P&gt;
&lt;P&gt;|sort by AccountNumber,_time&lt;/P&gt;
&lt;P&gt;|streamstats&amp;nbsp; range(_time) as diff window=2&lt;/P&gt;
&lt;P&gt;|eval DifferenceInTimeByEventtime=strftime(diff,"%M:%S")&lt;/P&gt;
&lt;P&gt;|table AccountNumber eventType _time&amp;nbsp;DifferenceInTimeByEventtime&lt;/P&gt;
&lt;P&gt;The query is working..However I need the time difference as per the algorithm. NOT ONLY as per the previous event .The algorithm is as follows&lt;/P&gt;
&lt;P&gt;A&amp;nbsp;&amp;nbsp;&amp;nbsp; eventType=newyork&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;B&amp;nbsp;&amp;nbsp;&amp;nbsp; eventType=california&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; B-A&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; eventType=boston&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C-B&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;D&amp;nbsp;&amp;nbsp;&amp;nbsp; eventType=houston&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D-C&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;E&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eventType=dallas&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; E-D &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;F&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eventType=dallas&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;F-D &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;G&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eventType=Irvine&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;G-E &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;H&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eventType=Irvine &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;H-F &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eventType=Atlanta&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; I-H&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;J&amp;nbsp;&amp;nbsp;&amp;nbsp; eventType=San Antonio&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;J-I &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;K&amp;nbsp;&amp;nbsp; eventType=San Antonio &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; K-I&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp; eventType=Mumbai&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;L-I &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;M&amp;nbsp;&amp;nbsp; eventType=Delhi&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; M-I&lt;/P&gt;
&lt;P&gt;I'm looking for a&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;_time difference according to the algorithm above&lt;/LI&gt;
&lt;LI&gt;Add Avg,Max,Min column to the search &amp;nbsp; &amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I would appreciate if there is a query optimization&lt;/P&gt;
&lt;P&gt;Thanks in Advance.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 22:13:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-time-difference-in-a-list-of-eventTypes-by/m-p/562325#M195570</guid>
      <dc:creator>iamsplunker</dc:creator>
      <dc:date>2021-08-05T22:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the _time difference in a list of eventTypes by algorithm (non-sequencial order)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-time-difference-in-a-list-of-eventTypes-by/m-p/562328#M195572</link>
      <description>&lt;P&gt;Why isn't I I-G and L L-J and M M-L as these would seem to fit a pattern or are these completely arbitrary which would make optimising the search rather difficult?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 22:47:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-time-difference-in-a-list-of-eventTypes-by/m-p/562328#M195572</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-05T22:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the _time difference in a list of eventTypes by algorithm (non-sequencial order)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-time-difference-in-a-list-of-eventTypes-by/m-p/562331#M195573</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;: That's an algorithm .. and need to calculate the difference in that format. I'm thinking ..May be&amp;nbsp; writing a sub search for each event type and give the logic for the calculation may work?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 23:18:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-time-difference-in-a-list-of-eventTypes-by/m-p/562331#M195573</guid>
      <dc:creator>iamsplunker</dc:creator>
      <dc:date>2021-08-05T23:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the _time difference in a list of eventTypes by algorithm (non-sequencial order)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-time-difference-in-a-list-of-eventTypes-by/m-p/562382#M195589</link>
      <description>&lt;P&gt;Try a case function e.g. case(row="B", timefromB-timefromA,row="C",timefromC-timefromB,...) where timefrom can be mvindex of all the times e.g. timefromA is mvindex(times,0). You can generate times with eventstats list(_time) as times&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 07:45:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-time-difference-in-a-list-of-eventTypes-by/m-p/562382#M195589</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-06T07:45:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the _time difference in a list of eventTypes by algorithm (non-sequencial order)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-time-difference-in-a-list-of-eventTypes-by/m-p/564615#M196683</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;:&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm able to write the query for the difference ..however I'm not able to map the difference with _time. Is this something you could help?&lt;/P&gt;&lt;P&gt;I used the below query to get the difference as per the algorithm (D1,D2,D3 .. are difference, E as EventType T as _time)&lt;/P&gt;&lt;P&gt;| sort by _time,AccountNumber&lt;BR /&gt;| stats list(eventType) as E list(_time) as T by AccountNumber&lt;BR /&gt;| eval T0=(mvindex(T,0))&lt;BR /&gt;| eval T1=(mvindex(T,1))&lt;BR /&gt;| eval D1=T1-T0&lt;BR /&gt;| fieldformat D1= strftime(D1,"%M:%S")&lt;/P&gt;&lt;P&gt;| eval T2=(mvindex(T,2))&lt;BR /&gt;| eval T3=(mvindex(T,3))&lt;BR /&gt;| eval D2=T2-T1&lt;BR /&gt;| fieldformat D2= strftime(D2,"%M:%S")&lt;/P&gt;&lt;P&gt;| eval T4=(mvindex(T,4))&lt;BR /&gt;| eval T5=(mvindex(T,5))&lt;BR /&gt;| eval D3=T3-T2&lt;BR /&gt;| fieldformat D3= strftime(D3,"%M:%S")&lt;/P&gt;&lt;P&gt;---&lt;BR /&gt;| table AccountNumber E T D1 D2 D3 D4 D5&lt;/P&gt;&lt;P&gt;My resultes are showing like this&lt;/P&gt;&lt;P&gt;AccountNumber&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;E&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;T&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;D1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; D2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; D3&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;D4&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; D5&lt;/P&gt;&lt;P&gt;123456789&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NewYork&amp;nbsp; &amp;nbsp; 1/1/2021:12:30&amp;nbsp; &amp;nbsp; 30:00&amp;nbsp; 30:00&amp;nbsp; 30:00&amp;nbsp; &amp;nbsp;30:00&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;30:00&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;California&amp;nbsp; 1/1/2021:01:00&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Boston&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1/1/2021:01:30&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Houston&amp;nbsp; &amp;nbsp; &amp;nbsp; 1/1/2021:02:00&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Dallas&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1/1/2021:02:30&lt;/P&gt;&lt;P&gt;I do not want the D1,D2,D3,D4,D5 Columns .. I want Difference Column Mapped with T (side by side)along with AccountNumber E T. Please help&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 22:43:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-time-difference-in-a-list-of-eventTypes-by/m-p/564615#M196683</guid>
      <dc:creator>iamsplunker</dc:creator>
      <dc:date>2021-08-24T22:43:28Z</dc:date>
    </item>
  </channel>
</rss>

