<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: avoid latest timestamp in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/avoid-latest-timestamp/m-p/324391#M96801</link>
    <description>&lt;P&gt;You can filter the first event by doing a streamstats and removing event with count=1 and then take the difference between the min and max time -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &amp;lt;base search&amp;gt;   | streamstats count | where count!=1 | eval time=round(_time) | stats max(time) as max_time,min(time) as min_time | eval diff(mins)=strftime(max_time-min_time,"%M")
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 01 Jun 2017 09:29:32 GMT</pubDate>
    <dc:creator>dineshraj9</dc:creator>
    <dc:date>2017-06-01T09:29:32Z</dc:date>
    <item>
      <title>avoid latest timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/avoid-latest-timestamp/m-p/324390#M96800</link>
      <description>&lt;P&gt;Hi Team, &lt;/P&gt;

&lt;P&gt;There is a scenario where I need to calculate time range. I have to ignore latest timestamp and need to calculate the time range for remaining records.&lt;/P&gt;

&lt;P&gt;for eg.. &lt;/P&gt;

&lt;P&gt;17/05/2017 15:56:27.065   XXXX................&lt;BR /&gt;
17/05/2017 15:46:27.065   YYYYY.................&lt;BR /&gt;
17/05/2017  15:36:27.065   ZZZZZ........&lt;/P&gt;

&lt;P&gt;so it should give me 10 mins instead of 20 mins. &lt;/P&gt;

&lt;P&gt;can you please help? Can you please suggest how can I do that? &lt;/P&gt;

&lt;P&gt;Thanks and regards,&lt;BR /&gt;
Arjit goswami. &lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 09:07:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/avoid-latest-timestamp/m-p/324390#M96800</guid>
      <dc:creator>arjitgoswami</dc:creator>
      <dc:date>2017-06-01T09:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: avoid latest timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/avoid-latest-timestamp/m-p/324391#M96801</link>
      <description>&lt;P&gt;You can filter the first event by doing a streamstats and removing event with count=1 and then take the difference between the min and max time -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &amp;lt;base search&amp;gt;   | streamstats count | where count!=1 | eval time=round(_time) | stats max(time) as max_time,min(time) as min_time | eval diff(mins)=strftime(max_time-min_time,"%M")
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 01 Jun 2017 09:29:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/avoid-latest-timestamp/m-p/324391#M96801</guid>
      <dc:creator>dineshraj9</dc:creator>
      <dc:date>2017-06-01T09:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: avoid latest timestamp</title>
      <link>https://community.splunk.com/t5/Splunk-Search/avoid-latest-timestamp/m-p/324392#M96802</link>
      <description>&lt;P&gt;@arjitgoswami, can you add your existing search?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 10:01:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/avoid-latest-timestamp/m-p/324392#M96802</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-06-01T10:01:07Z</dc:date>
    </item>
  </channel>
</rss>

