Splunk Search

## How do you perform a mathematical calculation on the results of two queries?

I have two queries:
1. ```index=abc slice_played slicer=Latency externalUserID="\$ext\$" assetID="806d682119ac46d18b9f4a5f3dc20b10" | dedup time, sessionID | stats sum(duration) as "x_seconds"```

Let's say the result is x

1. ```index=abc slice_played slicer=Latency externalUserID="\$ext\$" assetID!="806d682119ac46d18b9f4a5f3dc20b10" assetID!="5c117f3141244a3a9d6899395b5c65aa" assetID!="d4da85ca8a474316a958a1d164d51483" | dedup time, sessionID | stats sum(duration) as "y_seconds"```

Let's say the result is y

Does something like this work?

``````index=abc slice_played slicer=Latency externalUserID="\$ext\$" assetID="806d682119ac46d18b9f4a5f3dc20b10"
| dedup time, sessionID
| stats sum(duration) as "x_seconds"
| appendcols
[ index=abc slice_played slicer=Latency externalUserID="\$ext\$" assetID!="806d682119ac46d18b9f4a5f3dc20b10" assetID!="5c117f3141244a3a9d6899395b5c65aa" assetID!="d4da85ca8a474316a958a1d164d51483"
| dedup time, sessionID
| stats sum(duration) as "y_seconds"]
| eval Result=(x_seconds/y_seconds)*100
| fields Result
``````

That is how I would start.

Yes it does!!! Thank you!! 🙂

