Splunk Search

I want number of days between two events in splunk search?

uagraw01
Motivator

My query

index=main source=secure.log sourcetype=*
| stats earliest(_time) as start, latest(_time) as stop
| eval start=strftime(start, "%m/%d/%y") | eval stop=strftime(stop, "%m/%d/%y") | eval days = round((start-stop)/86400). Please refer my below result.

start stop
11/16/18 11/23/18

Here i can see start and stop date but want to find difference between start and stop so i can found number of days gap between them. So in above result i wants days column and difference is 7 days. But days column is not coming here. Please suggest.

Tags (1)
0 Karma

493669
Super Champion

try below-

| eval start = strptime(start , "%m/%d/%y")| eval stop = strptime(stop, "%m/%d/%y")| eval days= round((stop-start)/86400)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...