Splunk Search

How do I subtract values from different events and fields based on a common field?

thomaszheng
New Member

Please help, I'm stuck on this problem for a while. Basically, lets say I have different events with fields like this. Basically I need a way to subtract a count from two different fields from two different events. Those two events only have 1 common field to somehow tie them together.

Event1)
session_id: 123 error: 1

Event2)
session_id: 123 request: 1 email: [email protected]
session_id: 123 request: 1 email: [email protected]
session_id: 321 request: 1 email: [email protected]

Result)
email request successful_request
[email protected] 2 1
[email protected] 1 1

Tags (2)
0 Karma

arjunpkishore5
Motivator

Try this. Please mark as answer if this works for you.

|union 
   [search 1]
   [search 2]
| stats values(email) as email, sum(request) as request, sum(error) as error by session_id
| eval successful_request=request - error
| fields - error, session_id
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...