Other Usage

Time difference between 2 events

manas
Explorer

I have 2 events :

Event 1 :

Timestamp A  UserID:ABC  startevent 

Event 2: 

Timestamp B  ID:ABC  endevent

I want to find time difference between start event and end event . In first event field is named "UserID" and in second event field is named "ID" .These two fields holds the value of the user for which start and subsequent end event is generated.

 

How can i get time difference here ? To use transaction i need a shared field .When i use transaction like below:

 

| transaction userId startswith=(event="startevent") endswith=("endevent") maxevents=2 , i get very few results .

 

 

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You have a common field, just not a common name.  That's easy to fix using the coalesce function.

index=foo (UserID=* OR ID=*)
| eval commonID=coalesce(UserID, ID)
| stats min(_time) as startTime, max(_time) as endTime, values(*) as * by commonID
| eval diff=endTime - startTime

 

---
If this reply helps you, Karma would be appreciated.

manas
Explorer

Thanks .Used coalesce and transaction to get the data. 

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...