Splunk Search

Time difference between 2 results, grouped by day

cs97jb
New Member

I have a search that returns two results per day (a job's log entry of when it started and when it ended). I want to be able to see the time difference between the two entries, grouped by day.

I'm a newbie to Splunk advanced searching so hopefully you can help.

My query is:

index=main ExportConfigInfo AND ("Message=Job started" OR "Message=Job completed")

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

index=main ExportConfigInfo "MessageJob started" OR "MessageJob completed"
| eval start=if(searchmatch("MessageJob started"),_time,null())
| eval end=if(searchmatch("MessageJob completed"),_time,null())
| bin _time span=1d
| stats min(start) as start, max(end) as end by _time
| eval diff=end-start
| eval difference=tostring(diff, "duration")
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...