Splunk Search

Substract actual field with previous event field

lpolo
Motivator

I have the following summary index

_time               Type        Number
11/14/11 3:00:53.000 PM     New     56802
11/14/11 2:00:44.000 PM     New     56581
11/14/11 1:01:00.000 PM     New     56459
11/14/11 12:00:51.000 PM    New     56327
11/14/11 11:00:42.000 AM    New     56187
11/14/11 10:00:58.000 AM    New     55998
11/14/11 9:01:08.000 AM     New     55724
11/14/11 8:01:12.000 AM     New     55282

I have been not able to find a query that substract the last event "Number" with the previous one. For example

Events:

_time               Type        Number
11/14/11 3:00:53.000 PM     New     56802
11/14/11 2:00:44.000 PM     New     56581

New Number = 56802 - 56581

Result set:

New Number = 301

Thanks,

Tags (2)
1 Solution

Ayn
Legend

Ayn
Legend

This is precisely what you could use the delta command for.

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Delta

Ayn
Legend

No problem. Could you please mark my answer as accepted? Thanks!

0 Karma

lpolo
Motivator

Thanks for your help

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...