Dashboards & Visualizations

Regarding Splunk Search

New Member

I have a requirement wherein i have 3 columns, Owning_stream, changeReq Number, Sate_id (proposed, awaiting approval etc). I am able to calculate the maximum of _time group by State_id. But i want to add one more column in the final result which displays the difference between maximum and minimum dates from previous column. 

Labels (1)
0 Karma


It's not clear to me what you seek, but perhaps this will help.

... | stats max(_time), range(_time) by State_id

The range function calculates the difference between the maximum and minimum values of the given field. 

If this reply helps you, an upvote would be appreciated.
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!