Splunk Search

how to get the average time for latest event and previous event

remoharish
Engager

I am looking for a solution to show for every latest event time and previous event time average duration (and the time span between them). Please help me to get this sorted out ( duration time : 19/06/2017 14:03:23.000 - 19/06/2017 14:03:21.000 = 0.2 min).

Latest event:

19/06/2017
14:03:23.000

<[H8C8B5E4487854A2] Request sent

Previous Event:

19/06/2017
14:03:21.000

<[H8C8B5E4487854A2] Request sent

Tags (1)
0 Karma

cmerriman
Super Champion

use streamstats. http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/SearchReference/Streamstats

something like this:

...|sort 0 transaction _time
|streamstats window=1 current=f values(_time) as prevTime count as order by transaction
|eval deltaTime=_time-prevTime
|eval avgTime=(_time+prevTime)/2
|eventstats max(order) as maxOrder by transaction
|where maxOrder=order
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...