Splunk Search

## How do you perform a mathematical calculation on the results of two queries?

Path Finder

Hello,

I have two queries:
1. ```index=abc slice_played slicer=Latency externalUserID="\$ext\$" assetID="806d682119ac46d18b9f4a5f3dc20b10" | dedup time, sessionID | stats sum(duration) as "x_seconds"```

Let's say the result is x

1. ```index=abc slice_played slicer=Latency externalUserID="\$ext\$" assetID!="806d682119ac46d18b9f4a5f3dc20b10" assetID!="5c117f3141244a3a9d6899395b5c65aa" assetID!="d4da85ca8a474316a958a1d164d51483" | dedup time, sessionID | stats sum(duration) as "y_seconds"```

Let's say the result is y

Tags (2)
1 Solution
Contributor

Does something like this work?

``````index=abc slice_played slicer=Latency externalUserID="\$ext\$" assetID="806d682119ac46d18b9f4a5f3dc20b10"
| dedup time, sessionID
| stats sum(duration) as "x_seconds"
| appendcols
[ index=abc slice_played slicer=Latency externalUserID="\$ext\$" assetID!="806d682119ac46d18b9f4a5f3dc20b10" assetID!="5c117f3141244a3a9d6899395b5c65aa" assetID!="d4da85ca8a474316a958a1d164d51483"
| dedup time, sessionID
| stats sum(duration) as "y_seconds"]
| eval Result=(x_seconds/y_seconds)*100
| fields Result
``````

That is how I would start.

Contributor

Does something like this work?

``````index=abc slice_played slicer=Latency externalUserID="\$ext\$" assetID="806d682119ac46d18b9f4a5f3dc20b10"
| dedup time, sessionID
| stats sum(duration) as "x_seconds"
| appendcols
[ index=abc slice_played slicer=Latency externalUserID="\$ext\$" assetID!="806d682119ac46d18b9f4a5f3dc20b10" assetID!="5c117f3141244a3a9d6899395b5c65aa" assetID!="d4da85ca8a474316a958a1d164d51483"
| dedup time, sessionID
| stats sum(duration) as "y_seconds"]
| eval Result=(x_seconds/y_seconds)*100
| fields Result
``````

That is how I would start.

Path Finder

Yes it does!!! Thank you!! 🙂

Get Updates on the Splunk Community!

#### .conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

#### Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

#### Troubleshooting the OpenTelemetry Collector

In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...