I am writing a query here to calculate the expected frequency of data in an index :
| eval time_diff=_time-lag(_time)
| stats avg(time_diff) as avg_time_diff
However, when I try and run it, I receive the following error message:
I assumed Splunk has a lag function. I use it quiet a lot in my SQL queries. I need it to calculate the time difference between each event and the previous event. This is because I would then alculats the average value of the "time_diff" field, giving you an estimate of the expected frequency of data in the index.
if one answer solves your need, please accept one answer for the other people of Community or tell me how I can help you.
Ciao and happy splunking
P.S.: Karma Points are appreciated 😉