Hi,
I am writing a query here to calculate the expected frequency of data in an index :
index=ABC
| eval time_diff=_time-lag(_time)
| stats avg(time_diff) as avg_time_diff
However, when I try and run it, I receive the following error message:
Hi @POR160893,
yes there's this function, it's "delta" (https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Delta)
Ciao.
Giuseppe
Hi @POR160893,
sorry: where did you find the lag function?
what do you want to calculate with it?
Ciao.
Giuseppe
I assumed Splunk has a lag function. I use it quiet a lot in my SQL queries. I need it to calculate the time difference between each event and the previous event. This is because I would then alculats the average value of the "time_diff" field, giving you an estimate of the expected frequency of data in the index.
Hi @POR160893,
yes there's this function, it's "delta" (https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Delta)
Ciao.
Giuseppe
Thanks, I changed my query to this then:
Hi @POR160893,
if one answer solves your need, please accept one answer for the other people of Community or tell me how I can help you.
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉