Splunk Search

Calculate Lag time between events

parmenion_natha
Explorer

I am trying to calculate lag time but have the following issues:

_time is the same for each event as the data is indexed in chunks.

I am trying to take the highest result from field access-time and calculate the difference between the second highest result.

Something like |eval resultA - resultB.  How do I get the 2 latest results from field access-time and calculate the difference

2020-11-13 08:18:371605254674
2020-11-13 08:18:371605254590
2020-11-13 08:18:371605253080
2020-11-13 08:18:371605252671
2020-11-13 08:18:371605251083
2020-11-13 08:18:371605250993
2020-11-13 08:18:371605249063
2020-11-13 08:18:371605247382
2020-11-13 08:18:371605245462
2020-11-13 08:18:371605243784
2020-11-13 08:18:371605241862
2020-11-13 08:18:371605240185
2020-11-13 08:18:371605238263
2020-11-13 08:18:371605236583
2020-11-13 08:18:371605234662
2020-11-13 08:18:371605232983
2020-11-13 08:18:371605231063
2020-11-13 08:18:371605229384
2020-11-13 08:18:371605227467
2020-11-13 08:18:371605225783
2020-11-13 08:18:371605223863
2020-11-13 08:18:371605222196
2020-11-13 08:18:371605220274
2020-11-13 08:18:371605218605
2020-11-13 08:18:371605216684
2020-11-13 08:18:371605214996
Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| autoregress field1 as previous1 p=1
| eval diff=field1-previous1

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| autoregress field1 as previous1 p=1
| eval diff=field1-previous1
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...