Splunk Search

How to modify delta search to convert negative values in results to positive values?

nramya82
Explorer

Hi ,

I need to make a graph for the delta_f where i am finding the difference of current value and next value . By using the query below I get some negative values. Can any one help me find what needs to be added in my search to convert all the negative values into positive values?

|search abc| eval delta_f= nextValues - currentValues | timechart span=1d sum(delta_f)

eg: say for delta_f = (nextvalue) - (currentvalue)

0000986 - 5362722 = -5361736 Instead i want only 5361736

Tags (1)
1 Solution

adauria_splunk
Splunk Employee
Splunk Employee

Pipe results to an eval statement like

eval delta_f = abs(delta_f)

Which converts to absolute value

View solution in original post

adauria_splunk
Splunk Employee
Splunk Employee

Pipe results to an eval statement like

eval delta_f = abs(delta_f)

Which converts to absolute value

nramya82
Explorer

Yep that worked . Thanks a lot !

0 Karma

ppablo
Retired

Hi @nramya82

Glad @adauria_splunk helped you find your solution 🙂 You used eval to find the difference between your field values, but there actually is a delta command for this purpose, just so you know for future reference. Check out the documentation for it here:
http://docs.splunk.com/Documentation/Splunk/6.1.4/SearchReference/Delta

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...