Splunk Search

mulitvalue and single value difference

nehamvinchankar
Path Finder

How to get difference of  lastest value with now i have multiple values in latest column and only one value in now column i want output as difference 

latestnow
1701973800.000000
1701455400.000000
1701455400.000000
1700418600.000000
1700418600.000000
1702372339

 

1701973800.000000- 1702372339 =

1701455400.000000- 1702372339= 

like this 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| mvexpand latest
| eval diff=now - latest

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| mvexpand latest
| eval diff=now - latest
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...