Splunk Search

How to Calculate the difference between two rows of a column?

Splunk_321
Path Finder

I have a splunk query shown below.

 

 

 

basesearch
| stats avg(time) as executionTime by method

 

 

 

which results in table like below

 

 

 

method               executionTime
A                        110.350
B                         90.150

 

 

 

I want to obtain executionTime difference between method A and B in a table result

A-B = 20.20

Please help me with splunk query to get the same.

Thanks in advance!

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Splunk_321,

you have to put them in the same row, something like this:

basesearch
| stats 
   avg(eval(if(method="A"),time,0)) as executionTime_A
   avg(eval(if(method="B"),time,0)) as executionTime_B
| eval diff=executionTime_B-executionTime_A

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...