Splunk Search

How to Calculate the difference between two rows of a column?

Splunk_321
Path Finder

I have a splunk query shown below.

 

 

 

basesearch
| stats avg(time) as executionTime by method

 

 

 

which results in table like below

 

 

 

method               executionTime
A                        110.350
B                         90.150

 

 

 

I want to obtain executionTime difference between method A and B in a table result

A-B = 20.20

Please help me with splunk query to get the same.

Thanks in advance!

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Splunk_321,

you have to put them in the same row, something like this:

basesearch
| stats 
   avg(eval(if(method="A"),time,0)) as executionTime_A
   avg(eval(if(method="B"),time,0)) as executionTime_B
| eval diff=executionTime_B-executionTime_A

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...