Splunk Search

Find the diff between two times

luckyman80
Path Finder

Hi I am really struggling to find the difference between the 51= time and the 59= time below and add to a separate column

My log extract example is 

2021-01-06 12:37:57.411 [FIDO1] INFO LogAuditor - [FIDO2] Outgoing [12294][0] : 8=FIX.4.49=54135=D49=FIDO156=FIDO2_192_168_0_134=1599251=20210106-17:37:57.41011=1609686062170-FIDO15140WTZ00087815=USD21=138=100000040=244=19.632154=255=PECEOF59=359=20210106-17:37:57.409

Thanks in advance experts 

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Sorry about that.   There were some typos in my answer.  I've fixed them.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

luckyman80
Path Finder

i actually noticed there is an issue with the strp time as there is no results given when i table the diff and epoch51/epoch59 items 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Sorry about that.   There were some typos in my answer.  I've fixed them.

---
If this reply helps you, Karma would be appreciated.

richgalloway
SplunkTrust
SplunkTrust

First, we need to extract the fields.  Then we convert the timestamps into epoch form.  Finally, we can compute the difference.

 

<your search>
| rex "51=(?<ts51>\d{8}-\d\d:\d\d:\d\d\.\d{3})"
| rex "59=(?<ts59>\d{8}-\d\d:\d\d:\d\d\.\d{3})"
| eval epoch51=strptime(ts51,"%Y%m%d-%H:%M:%S.%3N"), epoch59=strptime(ts59,"%Y%m%d-%H:%M:%S.%3N")
| eval diff=epoch59 - epoch51

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

luckyman80
Path Finder

hi thanks for this. I still am unable to see the def in a separate column. Whats the best way of displaying the results for the diff ? in a table ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...