Splunk Search

How to Calculate the difference between two rows of a column?

Splunk_321
Path Finder

I have a splunk query shown below.

 

 

 

basesearch
| stats avg(time) as executionTime by method

 

 

 

which results in table like below

 

 

 

method               executionTime
A                        110.350
B                         90.150

 

 

 

I want to obtain executionTime difference between method A and B in a table result

A-B = 20.20

Please help me with splunk query to get the same.

Thanks in advance!

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Splunk_321,

you have to put them in the same row, something like this:

basesearch
| stats 
   avg(eval(if(method="A"),time,0)) as executionTime_A
   avg(eval(if(method="B"),time,0)) as executionTime_B
| eval diff=executionTime_B-executionTime_A

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...