Other Usage

Error in 'streamstats' command: The argument 'diff(count)' is invalid.

POR160893
Builder

I am running the following query:

index="ABCi" sourcetype=DEF
| timechart span=1h count
| fields - _time
| streamstats current=t diff(count) as count_diff
| stats avg(count_diff)


BUT, I am receiving the following error:

Error in 'streamstats' command: The argument 'diff(count)' is invalid.

Can you please help?

Thanks


0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

diff() isn't a stats aggregation function - you could use range() instead, and perhaps a window size of 2

| streamstats current=t window=2 diff(count) as count_diff

 

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...