Splunk Search

avoid latest timestamp

New Member

Hi Team,

There is a scenario where I need to calculate time range. I have to ignore latest timestamp and need to calculate the time range for remaining records.

for eg..

17/05/2017 15:56:27.065 XXXX................
17/05/2017 15:46:27.065 YYYYY.................
17/05/2017 15:36:27.065 ZZZZZ........

so it should give me 10 mins instead of 20 mins.

can you please help? Can you please suggest how can I do that?

Thanks and regards,
Arjit goswami.

Tags (2)
0 Karma
1 Solution

Builder

You can filter the first event by doing a streamstats and removing event with count=1 and then take the difference between the min and max time -

 <base search>   | streamstats count | where count!=1 | eval time=round(_time) | stats max(time) as max_time,min(time) as min_time | eval diff(mins)=strftime(max_time-min_time,"%M")

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

@arjitgoswami, can you add your existing search?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

Builder

You can filter the first event by doing a streamstats and removing event with count=1 and then take the difference between the min and max time -

 <base search>   | streamstats count | where count!=1 | eval time=round(_time) | stats max(time) as max_time,min(time) as min_time | eval diff(mins)=strftime(max_time-min_time,"%M")

View solution in original post

0 Karma