Dashboards & Visualizations

Regarding Splunk Search

AnujaT
New Member

I have a requirement wherein i have 3 columns, Owning_stream, changeReq Number, Sate_id (proposed, awaiting approval etc). I am able to calculate the maximum of _time group by State_id. But i want to add one more column in the final result which displays the difference between maximum and minimum dates from previous column. 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not clear to me what you seek, but perhaps this will help.

... | stats max(_time), range(_time) by State_id

The range function calculates the difference between the maximum and minimum values of the given field. 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...