I have a tabled results of _time. Each one is an event and I want to find a difference for each event and have the value in another field.
index=
c_time
======
2014-09-11 00:56:24:677
2014-09-11 00:56:24:677
2014-09-11 00:56:24:676
2014-09-11 00:56:24:676
2014-09-11 00:56:24:676
2014-09-11 00:41:24:664
2014-09-11 00:41:24:664
I want to be able to get the difference between each event and chart them by the c_time.
What is the best possible way of achieving this?
Try using the delta command like so:
index=<index_name> sourcetype=<sourcetype_name> | convert timeformat="%Y-%m-%d %H:%M:%S:%3N" ctime(_time) AS c_time |delta c_time as time_difference | table c_time time_difference
For more information: http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Delta
Try using the delta command like so:
index=<index_name> sourcetype=<sourcetype_name> | convert timeformat="%Y-%m-%d %H:%M:%S:%3N" ctime(_time) AS c_time |delta c_time as time_difference | table c_time time_difference
For more information: http://docs.splunk.com/Documentation/Splunk/6.1.3/SearchReference/Delta
Yes. Exactly. I was too lazy to do that in my answer 😄
Thank you for the quick response, looks like I need to do more homework on this. All I have to do is convert the time_difference to a format that is human readable for users.