Splunk Search

Calculate Lag time between events

parmenion_natha
Explorer

I am trying to calculate lag time but have the following issues:

_time is the same for each event as the data is indexed in chunks.

I am trying to take the highest result from field access-time and calculate the difference between the second highest result.

Something like |eval resultA - resultB.  How do I get the 2 latest results from field access-time and calculate the difference

2020-11-13 08:18:371605254674
2020-11-13 08:18:371605254590
2020-11-13 08:18:371605253080
2020-11-13 08:18:371605252671
2020-11-13 08:18:371605251083
2020-11-13 08:18:371605250993
2020-11-13 08:18:371605249063
2020-11-13 08:18:371605247382
2020-11-13 08:18:371605245462
2020-11-13 08:18:371605243784
2020-11-13 08:18:371605241862
2020-11-13 08:18:371605240185
2020-11-13 08:18:371605238263
2020-11-13 08:18:371605236583
2020-11-13 08:18:371605234662
2020-11-13 08:18:371605232983
2020-11-13 08:18:371605231063
2020-11-13 08:18:371605229384
2020-11-13 08:18:371605227467
2020-11-13 08:18:371605225783
2020-11-13 08:18:371605223863
2020-11-13 08:18:371605222196
2020-11-13 08:18:371605220274
2020-11-13 08:18:371605218605
2020-11-13 08:18:371605216684
2020-11-13 08:18:371605214996
Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| autoregress field1 as previous1 p=1
| eval diff=field1-previous1

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| autoregress field1 as previous1 p=1
| eval diff=field1-previous1
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...