Other Usage

Error in 'streamstats' command: The argument 'diff(count)' is invalid.

POR160893
Builder

I am running the following query:

index="ABCi" sourcetype=DEF
| timechart span=1h count
| fields - _time
| streamstats current=t diff(count) as count_diff
| stats avg(count_diff)


BUT, I am receiving the following error:

Error in 'streamstats' command: The argument 'diff(count)' is invalid.

Can you please help?

Thanks


0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

diff() isn't a stats aggregation function - you could use range() instead, and perhaps a window size of 2

| streamstats current=t window=2 diff(count) as count_diff

 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...