Getting Data In

How can I compare values from the same field at different timestamps?

slipinski
Path Finder

I trying to create a graph which will be display difference beetwen values at different time.
"2018-07-10 15:37:16,395 Mem: 683 MB GC: 436 GCT: 11475 ms"
2018-07-10 15:36:16,395 Mem: 625 MB GC: 434 GCT: 11430 ms"
"2018-07-10 15:35:16,395 Mem: 868 MB GC: 431 GCT: 11365 ms"

I would like to create a graph with GC difeferences .i.e last minute=2, 2 minutes ago=3 and so on.
Any advice?

Thanks

Szymon

Tags (2)
0 Karma

renjith_nair
Legend

Hi @slipinski,

You could use delta command if you want difference between continuous events

e.g. "your search"|delta GC  as diff | filnull value=0

Used this to extract the field, base search | rex field=_raw "^(?:[^ \n]* ){6}(?P<GC>\d+)" |table GC

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...