Splunk Search

Calculate Lag time between events

parmenion_natha
Explorer

I am trying to calculate lag time but have the following issues:

_time is the same for each event as the data is indexed in chunks.

I am trying to take the highest result from field access-time and calculate the difference between the second highest result.

Something like |eval resultA - resultB.  How do I get the 2 latest results from field access-time and calculate the difference

2020-11-13 08:18:371605254674
2020-11-13 08:18:371605254590
2020-11-13 08:18:371605253080
2020-11-13 08:18:371605252671
2020-11-13 08:18:371605251083
2020-11-13 08:18:371605250993
2020-11-13 08:18:371605249063
2020-11-13 08:18:371605247382
2020-11-13 08:18:371605245462
2020-11-13 08:18:371605243784
2020-11-13 08:18:371605241862
2020-11-13 08:18:371605240185
2020-11-13 08:18:371605238263
2020-11-13 08:18:371605236583
2020-11-13 08:18:371605234662
2020-11-13 08:18:371605232983
2020-11-13 08:18:371605231063
2020-11-13 08:18:371605229384
2020-11-13 08:18:371605227467
2020-11-13 08:18:371605225783
2020-11-13 08:18:371605223863
2020-11-13 08:18:371605222196
2020-11-13 08:18:371605220274
2020-11-13 08:18:371605218605
2020-11-13 08:18:371605216684
2020-11-13 08:18:371605214996
Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| autoregress field1 as previous1 p=1
| eval diff=field1-previous1

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| autoregress field1 as previous1 p=1
| eval diff=field1-previous1
0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...