Getting Data In

To calculate difference of first event and last event in the log

angalakuditived
Loves-to-Learn

Hi ,

 

I have to calculate the time difference between first event and last event for a particular flow in log I have used earliest (_time) and latest(_time) which gave me correct data.

Index= * | stats earliest(_time) as Earliest and latest (_time) as Latest 

Gave output in epoch Times but I need difference of Earliest and Latest,tried using diff and eval diff to strf time but no luck.

 

Can someone help me with the query please

 

 

 

 

 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Doesn't this give you the difference (in seconds)?

| eval diff=Latest-Earliest
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...