Splunk Search

How to remove missing value timestamps for accurate delta calculation

Bart
Explorer

HI,

I'm running a search for two different timeranges, for missing datapoint pair it's creating discrepancy with my calculations.
I need accurate diff so fillnull value is not an option, I would prefer want to remove _time row if it's missing a pair for the same timestamp, any hints appreciated.

timedelta.png

Got an idea with below but despite moving around my stats 

| stats count values(marker) as pairstamp by _time
| where count=2

count2.png

Labels (3)
0 Karma

Bart
Explorer

my search is:
earliest="4/1/2024:00:00:00" latest="8/1/2024:00:00:00"

| bin span=1h _time
| addinfo
| eval marker = if(_time < (relative_time(info_min_time,"+1mon@mon")), "April", "July")
| eval _time = if(_time < (relative_time(info_min_time,"+1mon@mon")), _time + 91*24*3600, _time)
...
| where _time>=relative_time(now(), "-1mon@mon")
| stats max(sig_value) as signature by _time marker
| delta signature as diff_delta
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try using eventstats

| eventstats count by _time
| where count=2
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...