<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to delete events which is decreasing inbetween? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648091#M224264</link>
    <description>&lt;P&gt;How to delete events which is decreasing inbetween. I have extracted the _time column using regex so that splunk default sorting won't happens.&lt;/P&gt;
&lt;TABLE width="290"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;_time&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;Warning&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:55.7852&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:56.2278&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:56.2278&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:56.3939&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:39.2861&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:40.3430&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;ERROR&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:41.3482&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:41.4832&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;WARN&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:41.7433&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;WARN&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:41.7433&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:41.7433&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:54.8140&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;ERROR&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:55.4640&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:55.8192&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:56.8794&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:57.8846&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:58.9398&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:59.9450&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;WARN&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:59.9700&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:59.9700&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:27:00.8201&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:27:00.8401&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:27:01.0352&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:27:00.8901&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:27:00.8701&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:27:01.0452&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It should ignore the events which i marked in "arial black", because "seconds" value starting decreasing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jun 2023 15:35:33 GMT</pubDate>
    <dc:creator>kirthika26</dc:creator>
    <dc:date>2023-06-26T15:35:33Z</dc:date>
    <item>
      <title>How to delete events which is decreasing inbetween?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648091#M224264</link>
      <description>&lt;P&gt;How to delete events which is decreasing inbetween. I have extracted the _time column using regex so that splunk default sorting won't happens.&lt;/P&gt;
&lt;TABLE width="290"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;_time&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;Warning&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:55.7852&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:56.2278&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:56.2278&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:56.3939&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:39.2861&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:40.3430&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;ERROR&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:41.3482&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:41.4832&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;WARN&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:41.7433&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;WARN&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:41.7433&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:41.7433&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:54.8140&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;ERROR&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:55.4640&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:55.8192&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:56.8794&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:57.8846&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:58.9398&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:59.9450&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;WARN&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:59.9700&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:26:59.9700&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:27:00.8201&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:27:00.8401&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;INFO&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:27:01.0352&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:27:00.8901&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:27:00.8701&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="219.087px" height="24px"&gt;2021-08-09 12:27:01.0452&lt;/TD&gt;
&lt;TD width="70.1125px" height="24px"&gt;ERROR&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It should ignore the events which i marked in "arial black", because "seconds" value starting decreasing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 15:35:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648091#M224264</guid>
      <dc:creator>kirthika26</dc:creator>
      <dc:date>2023-06-26T15:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648092#M224265</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254926"&gt;@kirthika26&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you could calculate delta (&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.5/SearchReference/Delta#:~:text=The%20delta%20command%20is%20used,default%20field%20name%20to%20timeDeltaS" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.5/SearchReference/Delta#:~:text=The%20delta%20command%20is%20used,default%20field%20name%20to%20timeDeltaS&lt;/A&gt;.) with the previous event and filter the negative ones:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| delta _time AS delta
| where delta&amp;gt;0
| table _time warning&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 08:51:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648092#M224265</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-06-24T08:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648097#M224268</link>
      <description>&lt;P&gt;Delta value is coming as "negative" or "zero" for all the rows. So can't able to delete the row.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 13:19:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648097#M224268</guid>
      <dc:creator>kirthika26</dc:creator>
      <dc:date>2023-06-24T13:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648101#M224269</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254926"&gt;@kirthika26&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;probably the timestamp you're using isn't _time, so, please try:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| eval timestamp=strptime(timestamp,"%Y-%m-%d %H:%M:%S.%4N")
| delta timestamp AS delta
| where delta&amp;gt;0
| table timestamp warning&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 14:29:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648101#M224269</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-06-24T14:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648107#M224270</link>
      <description>&lt;P&gt;What do you mean by "delete"? You don't want to show them in the results? And how would you want to find such events as search results are by default sorted in reverse chronological order?&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 15:50:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648107#M224270</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-06-24T15:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648108#M224271</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't want to show those rows in search result.&lt;/P&gt;&lt;P&gt;It won't be in sorted order since i extracted time by regex.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 16:37:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648108#M224271</guid>
      <dc:creator>kirthika26</dc:creator>
      <dc:date>2023-06-24T16:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648109#M224272</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried the same way, but can't able to get the desired results.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;| rex field=_raw "(?&amp;lt;timestamp&amp;gt;\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}.\d{4})"&lt;BR /&gt;| eval timestamp=strptime(timestamp,"%Y-%m-%d %H:%M:%S.%4N")&lt;BR /&gt;| delta timestamp AS delta&lt;BR /&gt;| table timestamp&amp;nbsp; delta&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Attached sample data in html.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;timestamp	delta
1635312047	
1635312047	-0.0156
1635312046	-0.3501
1628492228	-6819818.165
1628492227	-1.0652
1628492226	-1.0652
1628492225	-1.0052
1628492224	-1.0502
1628492223	-1.0052
1628492222	-1.0502
1628492221	-1.0052
1628492221	-0.1951
1628492221	-0.02
1628492220	-0.8501
1628492220	0
1628492220	-0.025
1628492219	-1.0052
1628492218	-1.0552
1628492217	-1.0052
1628492216	-1.0602
1628492215	-0.3552
1628492215	-0.65
1628492214	-1.0503
1628492213	-1.0052
1628492212	-1.0552
1628492211	-1.0043
1628492210	-0.8397
1628492210	-0.005
1628492210	-0.1842
1628492210	-0.005
1628492210	-0.02
1628492210	-0.025
1628492210	0
1628492210	0
1628492209	-0.9772
1628492208	-1.0584
1628492207	-1.0052
1628492206	-0.2851
1628492206	-0.01
1628492206	-0.01
1628492206	0
1628492206	-0.015
1628492206	-0.7351
1628492205	-0.3401
1628492205	0
1628492205	-0.6651
1628492203	-1.0502
1628492203	-0.2852
1628492203	0
1628492203	-0.01
1628492203	0
1628492203	0
1628492203	-0.01
1628492202	-0.7001
1628492202	-0.7201
1628492202	0
1628492202	0
1628492201	-0.2601
1628492201	-0.135
1628492200	-1.0052
1628492199	-1.0569
1628492216	17.1078
1628492216	-0.1661
1628492216	0
1628492216	-0.4426
1628492216	-0.05
1628492216	0
1628492215	-0.431
1628492215	-0.0854
1628492215	-0.5434
1628492215	-0.07
1628492215	-0.0611
1628492214	-0.1441
1628492214	-0.033
1628492214	-0.023
1628492214	-0.042
1628492214	-0.0511
1628492214	-0.01
1628492214	0
1628492214	-0.1271
1628492214	-0.037
1628492214	-0.034
1628492214	-0.017
1628492214	-0.0431
1628492214	-0.016
1628492214	-0.025
1628492214	-0.065
1628492214	-0.0351
1628492214	-0.039
1628492214	-0.054
1628492214	-0.1441
1628492214	-0.03
1628492214	-0.02
1628492214	-0.035
1628492213	-0.1901
1628492213	0
1628492213	0
1628492213	0
1628492213	-0.04
1628492213	-0.085
1628492213	0
1628492213	-0.01
1628492213	0
1628492213	-0.115
1628492213	-0.1651
1628492213	-0.015
1628492213	0
1628492213	0
1628492212	-0.4701
1628492212	0
1628492212	0
1628492212	-0.225
1628492212	-0.03
1628492212	-0.02
1628492212	-0.5801
1628492211	-0.6301
1628492211	0
1628492211	-0.01
1628492211	0
1628492211	0
1628492211	-0.1051
1628492211	-0.01
1628492211	-0.145
1628492211	-0.075
1628492211	-0.06
1628492210	-0.1
1628492210	-0.442
1628492210	-0.0156
1628492210	0
1628492210	-0.1094
1628492210	-0.1719
1628492210	-0.1562
1628492209	-0.0469
1628492209	-0.1406
1628492209	0
1628492209	-0.0312
1628492209	0
1628492209	-0.4688
1628492209	-0.0782
1628492209	-0.0312
1628492209	-0.0313
1628492209	-0.0156
1628492209	-0.0156
1628492209	0
1628492208	-0.3594
1626875194	-1617014.747
1626875194	-0.0065&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 24 Jun 2023 17:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648109#M224272</guid>
      <dc:creator>kirthika26</dc:creator>
      <dc:date>2023-06-24T17:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648110#M224273</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254926"&gt;@kirthika26&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| rex field=_raw "(?&amp;lt;timestamp&amp;gt;\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}.\d{4})"
| eval timestamp=strptime(timestamp,"%Y-%m-%d %H:%M:%S.%4N")
| delta timestamp AS delta
| eval timestamp=strftime(timestamp,"%Y-%m-%d %H:%M:%S.%4N")
| sort -_time 
| table _time timestamp delta&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 17:16:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648110#M224273</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-06-24T17:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648111#M224274</link>
      <description>&lt;P&gt;You need to share more information about your data and process. &amp;nbsp;For starters,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;"&lt;SPAN&gt;extracted the _time column using regex." How is _time before this extraction?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Regex produces strings in _time column. &amp;nbsp;Did you convert it to numeric representation with strptime as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;suggested? &amp;nbsp;"Delta value is coming as 'negative' or 'zero'" would imply that _time is already numeric. &amp;nbsp;But could you confirm?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;Did you sort (or otherwise alter order of events)&amp;nbsp;&lt;EM&gt;before&lt;/EM&gt; delta? &amp;nbsp;"Delta value is coming as 'negative' or 'zero' for all the rows" strongly suggests that the order has changed. &amp;nbsp;Base on the order in your original post, you would have gotten the following&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Warning&lt;/TD&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;TD&gt;delta&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:55.785&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:56.227&lt;/TD&gt;&lt;TD&gt;0.442600&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:56.227&lt;/TD&gt;&lt;TD&gt;0.000000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ERROR&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:56.393&lt;/TD&gt;&lt;TD&gt;0.166100&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:39.286&lt;/TD&gt;&lt;TD&gt;-17.107800&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ERROR&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:40.343&lt;/TD&gt;&lt;TD&gt;1.056900&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:41.348&lt;/TD&gt;&lt;TD&gt;1.005200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;WARN&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:41.483&lt;/TD&gt;&lt;TD&gt;0.135000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;WARN&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:41.743&lt;/TD&gt;&lt;TD&gt;0.260100&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:41.743&lt;/TD&gt;&lt;TD&gt;0.000000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:41.743&lt;/TD&gt;&lt;TD&gt;0.000000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ERROR&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:54.814&lt;/TD&gt;&lt;TD&gt;13.070700&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:55.464&lt;/TD&gt;&lt;TD&gt;0.650000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:55.819&lt;/TD&gt;&lt;TD&gt;0.355200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ERROR&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:56.879&lt;/TD&gt;&lt;TD&gt;1.060200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:57.884&lt;/TD&gt;&lt;TD&gt;1.005200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ERROR&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:58.939&lt;/TD&gt;&lt;TD&gt;1.055200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;WARN&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:59.945&lt;/TD&gt;&lt;TD&gt;1.005200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ERROR&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:59.970&lt;/TD&gt;&lt;TD&gt;0.025000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:26:59.970&lt;/TD&gt;&lt;TD&gt;0.000000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:27:00.820&lt;/TD&gt;&lt;TD&gt;0.850100&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:27:00.840&lt;/TD&gt;&lt;TD&gt;0.020000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ERROR&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:27:01.035&lt;/TD&gt;&lt;TD&gt;0.195100&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:27:00.890&lt;/TD&gt;&lt;TD&gt;-0.145100&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;INFO&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:27:00.870&lt;/TD&gt;&lt;TD&gt;-0.020000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ERROR&lt;/TD&gt;&lt;TD&gt;2021-08-09 12:27:01.045&lt;/TD&gt;&lt;TD&gt;0.175100&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;As you can see, only 3 rows are negative. &amp;nbsp;For all deltas to be negative, _time would have to be all in decremental order.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I realize that using delta alone is not a complete solution because delta is sometimes positive even when the time is older than a previous forwarded row, such as in this segment.&lt;/P&gt;&lt;TABLE width="328px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="174.015625px"&gt;_time&lt;/TD&gt;&lt;TD width="73px"&gt;Warning&lt;/TD&gt;&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;...&lt;/TD&gt;&lt;TD&gt;...&lt;/TD&gt;&lt;TD&gt;...&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;1&lt;/TD&gt;&lt;TD width="174.015625px" height="24px"&gt;2021-08-09 12:26:56.3939&lt;/TD&gt;&lt;TD width="73px" height="24px"&gt;ERROR&lt;/TD&gt;&lt;TD width="40px"&gt;&lt;SPAN&gt;0.166100&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;&lt;FONT face="arial black,avant garde"&gt;2&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="174.015625px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:39.2861&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="73px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;INFO&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="40px"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;SPAN&gt;-17.107800&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;&lt;FONT face="arial black,avant garde"&gt;3&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="174.015625px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;2021-08-09 12:26:40.3430&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="73px" height="24px"&gt;&lt;FONT face="arial black,avant garde"&gt;ERROR&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="40px"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;1.056900&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Before even attempting to calculate, could you answer a more fundamental question: What is so important in the original order that those "decremented" events must be removed (as opposed to simply sort according to your extracted _time)?&lt;/P&gt;&lt;P&gt;Here is an emulation used to calculate deltas in the order you presented:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw = "_time	Warning
2021-08-09 12:26:55.7852	INFO
2021-08-09 12:26:56.2278	INFO
2021-08-09 12:26:56.2278	INFO
2021-08-09 12:26:56.3939	ERROR
2021-08-09 12:26:39.2861	INFO
2021-08-09 12:26:40.3430	ERROR
2021-08-09 12:26:41.3482	INFO
2021-08-09 12:26:41.4832	WARN
2021-08-09 12:26:41.7433	WARN
2021-08-09 12:26:41.7433	INFO
2021-08-09 12:26:41.7433	INFO
2021-08-09 12:26:54.8140	ERROR
2021-08-09 12:26:55.4640	INFO
2021-08-09 12:26:55.8192	INFO
2021-08-09 12:26:56.8794	ERROR
2021-08-09 12:26:57.8846	INFO
2021-08-09 12:26:58.9398	ERROR
2021-08-09 12:26:59.9450	WARN
2021-08-09 12:26:59.9700	ERROR
2021-08-09 12:26:59.9700	INFO
2021-08-09 12:27:00.8201	INFO
2021-08-09 12:27:00.8401	INFO
2021-08-09 12:27:01.0352	ERROR
2021-08-09 12:27:00.8901	INFO
2021-08-09 12:27:00.8701	INFO
2021-08-09 12:27:01.0452	ERROR"
| multikv forceheader=1
| fields - _* linecount
| eval time = strptime(time, "%F %H:%M:%S.%4N")
| rename time as _time
| delta _time as delta&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 17:23:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648111#M224274</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-06-24T17:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648113#M224275</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for your reply. I tried your query,&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kirthika26_0-1687627979294.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25997iD7E69C7E157B2F73/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kirthika26_0-1687627979294.png" alt="kirthika26_0-1687627979294.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the marked rows should be deleted because seconds value decreasing in between.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Time before extraction will show the time when data is uploaded&lt;/P&gt;&lt;P&gt;Why I'm ignoring those rows mean, when i'm calculating some calculation, there is a huge difference in hrs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 17:47:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648113#M224275</guid>
      <dc:creator>kirthika26</dc:creator>
      <dc:date>2023-06-24T17:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648115#M224276</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kirthika26_0-1687628052889.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25998i92CA05FE4E8D9F6D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kirthika26_0-1687628052889.png" alt="kirthika26_0-1687628052889.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But those rows marked in red should be removed since seconds value starts decreasing. I have marked in blue color&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 17:35:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648115#M224276</guid>
      <dc:creator>kirthika26</dc:creator>
      <dc:date>2023-06-24T17:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648116#M224277</link>
      <description>&lt;P&gt;Ok, let me explain something to you. The results &lt;STRONG&gt;will&lt;/STRONG&gt; be in chronological order according to the default Splunk's _time field. Each event in Splunk has a _time field. So if you're "extracting the _time field by regex", you're overwriting its value after the event has already been found and retrieved from the index.&lt;/P&gt;&lt;P&gt;If the fields you're extracting manually this way is the main timestamp and should be the event's _time field, it means your source(s) is(are) not properly onboarded and no proper timestamp recognition/extraction is being performed on your events.&lt;/P&gt;&lt;P&gt;If, however the timestamp you're extracting is not the main timestamp of the event, you shouldn't extract it as _time but as some other-named field. It's not that it's technically wrong, it's just a matter of convention and good practices.&lt;/P&gt;&lt;P&gt;Anyway, if you get that field with regex, you just have a string value. Splunk doesn't know that it's a timestamp and cannot do any arithmetics or comparisons on that. You need to parse it with strptime function to get a numerical representation of the point in time (so called "unix timestamp"). Then you can try manipulating your data (most probably using streamstats).&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 17:52:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648116#M224277</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-06-24T17:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore timestamp events which is immediately decreasing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648122#M224282</link>
      <description>&lt;OL&gt;&lt;LI&gt;Could you confirm or deny that when&amp;nbsp;&lt;SPAN&gt;"Delta value is coming as 'negative' or 'zero'", you performed extra sort on _time? Or is the natural order already in &lt;EM&gt;decreasing&lt;/EM&gt; _time order so no exclusion should be necessary in the first place?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The section you marked are not all in decreasing order. &amp;nbsp;Only the &lt;U&gt;first one in the group&lt;/U&gt; (2021-08-09 12:26:39.286) &amp;nbsp;is 17 seconds earlier than the previous one (2021-08-09 12:26:56.393). &amp;nbsp;Not only is each of the following timestamps later than&amp;nbsp;2021-08-09 12:26:39.286 (first one in the group), but also each is later than the one preceding it. &amp;nbsp;For example, 2021-08-09 12:26:40.343 is 1 second later than&amp;nbsp;2021-08-09 12:26:39.286; 2021-08-09 12:26:41.348 is another 1 second later than&amp;nbsp;2021-08-09 12:26:40.343; and so on.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;What I really mean is: Why shouldn't these events be sorted to order (descending or ascending)? &amp;nbsp;Is there any significance/meaning of &lt;STRONG&gt;showing&lt;/STRONG&gt; the disorder? &amp;nbsp;You can simply do&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| sort _time&lt;/LI-CODE&gt;&lt;P&gt;and the disorder will disappear.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 20:53:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-events-which-is-decreasing-inbetween/m-p/648122#M224282</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-06-24T20:53:43Z</dc:date>
    </item>
  </channel>
</rss>

