Splunk Search

Substract actual field with previous event field

Motivator

I have the following summary index

_time               Type        Number
11/14/11 3:00:53.000 PM     New     56802
11/14/11 2:00:44.000 PM     New     56581
11/14/11 1:01:00.000 PM     New     56459
11/14/11 12:00:51.000 PM    New     56327
11/14/11 11:00:42.000 AM    New     56187
11/14/11 10:00:58.000 AM    New     55998
11/14/11 9:01:08.000 AM     New     55724
11/14/11 8:01:12.000 AM     New     55282

I have been not able to find a query that substract the last event "Number" with the previous one. For example

Events:

_time               Type        Number
11/14/11 3:00:53.000 PM     New     56802
11/14/11 2:00:44.000 PM     New     56581

New Number = 56802 - 56581

Result set:

New Number = 301

Thanks,

Tags (2)
1 Solution

Legend

Legend

Legend

No problem. Could you please mark my answer as accepted? Thanks!

0 Karma

Motivator

Thanks for your help

0 Karma