Splunk Search

Transaction substitution of multiple fields

joza89
Engager

Hi,

I would like to use transaction to calculate the difference between multiple fields.
with this...

index="test" | transaction ID startswith="start" endswith="end" | table ID Timestamp Value1 trigger duration

i get..

ID                 Timestamp            Value1        trigger            duration
123              04.11.14 15:00         44               start                60.00
                 04.11.14 15:01          30               end        

what i need is the difference of Value1 and the duration like this...

ID                 Timestamp            Value1        trigger            duration
123               04.11.14 15:00        14                                      60.00

Does anyone know how to subtract two Values in a Transaction?

Tags (2)
0 Karma
1 Solution

wpreston
Motivator

I would try using mvlist=Value1 inside your transaction declaration and then evaling the value you're looking for. Something like this.

index="test" 
| transaction ID startswith="start" endswith="end" mvlist=Value1 
| eval firstValue1=mvindex(Value1,0) 
| eval secondValue1=mvindex(Value1,1) 
| eval value1Diff=firstValue1 - secondValue1  
| table ID Timestamp value1Diff trigger duration

View solution in original post

wpreston
Motivator

I would try using mvlist=Value1 inside your transaction declaration and then evaling the value you're looking for. Something like this.

index="test" 
| transaction ID startswith="start" endswith="end" mvlist=Value1 
| eval firstValue1=mvindex(Value1,0) 
| eval secondValue1=mvindex(Value1,1) 
| eval value1Diff=firstValue1 - secondValue1  
| table ID Timestamp value1Diff trigger duration

joza89
Engager

Worked, Thank you for your help

0 Karma

jeremiahc4
Builder

Have you looked at addtotals or addcoltotals? I'm not 100% sure how they react inside of a transaction though. It might work for the duration, but for Value1 it looks like you'd really need a subtractcoltotals which doesn't exist.

0 Karma

joza89
Engager

Did not work, unfortunately.
i also tried eventstats sum(Value1) as sum value this gives me the sum of all Value1s and not only in that transaction.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...