Getting Data In

How can I compare values from the same field at different timestamps?

slipinski
Path Finder

I trying to create a graph which will be display difference beetwen values at different time.
"2018-07-10 15:37:16,395 Mem: 683 MB GC: 436 GCT: 11475 ms"
2018-07-10 15:36:16,395 Mem: 625 MB GC: 434 GCT: 11430 ms"
"2018-07-10 15:35:16,395 Mem: 868 MB GC: 431 GCT: 11365 ms"

I would like to create a graph with GC difeferences .i.e last minute=2, 2 minutes ago=3 and so on.
Any advice?

Thanks

Szymon

Tags (2)
0 Karma

renjith_nair
Legend

Hi @slipinski,

You could use delta command if you want difference between continuous events

e.g. "your search"|delta GC  as diff | filnull value=0

Used this to extract the field, base search | rex field=_raw "^(?:[^ \n]* ){6}(?P<GC>\d+)" |table GC

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...