Splunk Search

Subtraction

ccsfdave
Builder

Greetings,

I am looking to perform subtraction. I have formatted my search to get me down to specific values and lastly I am looking to perform subtraction.

    Stage           analyst Count
1   5. Completed    Marta   114
2   4. Selection    Marta   44

So what I would like is to return a single value of 70. Feels like I have done the heavy lifting already but am stuck on the final bit. Help?

Thanks,

Dave

Tags (2)
0 Karma
1 Solution

ccsfdave
Builder

|stats range(Count)

That did it for me. Thanks for looking!

View solution in original post

ccsfdave
Builder

|stats range(Count)

That did it for me. Thanks for looking!

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...