Splunk Search

Transaction substitution of multiple fields

joza89
Engager

Hi,

I would like to use transaction to calculate the difference between multiple fields.
with this...

index="test" | transaction ID startswith="start" endswith="end" | table ID Timestamp Value1 trigger duration

i get..

ID                 Timestamp            Value1        trigger            duration
123              04.11.14 15:00         44               start                60.00
                 04.11.14 15:01          30               end        

what i need is the difference of Value1 and the duration like this...

ID                 Timestamp            Value1        trigger            duration
123               04.11.14 15:00        14                                      60.00

Does anyone know how to subtract two Values in a Transaction?

Tags (2)
0 Karma
1 Solution

wpreston
Motivator

I would try using mvlist=Value1 inside your transaction declaration and then evaling the value you're looking for. Something like this.

index="test" 
| transaction ID startswith="start" endswith="end" mvlist=Value1 
| eval firstValue1=mvindex(Value1,0) 
| eval secondValue1=mvindex(Value1,1) 
| eval value1Diff=firstValue1 - secondValue1  
| table ID Timestamp value1Diff trigger duration

View solution in original post

wpreston
Motivator

I would try using mvlist=Value1 inside your transaction declaration and then evaling the value you're looking for. Something like this.

index="test" 
| transaction ID startswith="start" endswith="end" mvlist=Value1 
| eval firstValue1=mvindex(Value1,0) 
| eval secondValue1=mvindex(Value1,1) 
| eval value1Diff=firstValue1 - secondValue1  
| table ID Timestamp value1Diff trigger duration

joza89
Engager

Worked, Thank you for your help

0 Karma

jeremiahc4
Builder

Have you looked at addtotals or addcoltotals? I'm not 100% sure how they react inside of a transaction though. It might work for the duration, but for Value1 it looks like you'd really need a subtractcoltotals which doesn't exist.

0 Karma

joza89
Engager

Did not work, unfortunately.
i also tried eventstats sum(Value1) as sum value this gives me the sum of all Value1s and not only in that transaction.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...