I am working on metrics for management and was wondering if it was able to compute the delta between two date data fields in an event? For example, one field is the start date and the other is the end date. Can Splunk figure out how many days lapsed in-between the start and end date?
Assuming a standard date format (12-20-2010 08:20:25), you want to use the eval and convert search command:
...| convert timeformat='%m-%d-%Y %T' mktime(starttime) mktime(endtime) | eval duration=(endtime-starttime)/86400
This will tell you how many days (there are 86400 seconds in a day) elapsed between the starttime and the endtime. To do the arithmetic, we have to use the convert command to make standard date formats into epoch time (number of seconds since 1/1/1970).