Splunk Search

I want number of days between two events in splunk search?

uagraw01
Builder

My query

index=main source=secure.log sourcetype=*
| stats earliest(_time) as start, latest(_time) as stop
| eval start=strftime(start, "%m/%d/%y") | eval stop=strftime(stop, "%m/%d/%y") | eval days = round((start-stop)/86400). Please refer my below result.

start stop
11/16/18 11/23/18

Here i can see start and stop date but want to find difference between start and stop so i can found number of days gap between them. So in above result i wants days column and difference is 7 days. But days column is not coming here. Please suggest.

Tags (1)
0 Karma

493669
Super Champion

try below-

| eval start = strptime(start , "%m/%d/%y")| eval stop = strptime(stop, "%m/%d/%y")| eval days= round((stop-start)/86400)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...