Splunk Search

Inconsistent behavior with eval after stats

randeepbydesign
Engager

I have this query that matches two types of events, sending a request and receiving an answer. My goal is to take the time both of these happens to see how long the question/answer process takes:

 

index = "application" ("request sent" OR "answer received") 
| rex field=_raw ".*\s+:\s+(?<label>\w+).+\s+(?<guid>[a-z\d-]+)$" 
| eval status=if(label="answer","complete","start") 
| eval start_time=if(status="complete",null,_time), end_time=if(status="complete",_time,null) 
| stats min(start_time) as startT, min(end_time) as endT by guid 
| eval exportTimeInMinutes=abs(end_time-start_time)/60

 

 This query works fine and I use it as a template for others. But the problem I am having is that I want to see a screen stats table which includes the exportTimeInMinutes column. When I first write this query I got back a table with 4 columns: guid, startT, endT and exportTimeInMinutes

However, when I come back into the page in a future session I no longer see the last column. Sometimes refreshing the page allows it to show up, other times it does not. Is this a bug (or even worse... a feature)?

Labels (2)
0 Karma
1 Solution

anilchaithu
Builder

@randeepbydesign 

The output fields from line 5 of your SPL are startT, endT and guid.

The required inputs for eval is end_time & start_time which are not inline.

change eval statement as shown below.

| eval exportTimeInMinutes=abs(endT-startT)/60

 

 Hope this helps

View solution in original post

anilchaithu
Builder

@randeepbydesign 

The output fields from line 5 of your SPL are startT, endT and guid.

The required inputs for eval is end_time & start_time which are not inline.

change eval statement as shown below.

| eval exportTimeInMinutes=abs(endT-startT)/60

 

 Hope this helps

randeepbydesign
Engager

It definitely helped. Thank you so much!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...

Data Management Digest – July 2026

  Welcome to the July 2026 edition of Data Management Digest! As your trusted partner in data innovation, the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...