Splunk Search

mulitvalue and single value difference

nehamvinchankar
Path Finder

How to get difference of  lastest value with now i have multiple values in latest column and only one value in now column i want output as difference 

latestnow
1701973800.000000
1701455400.000000
1701455400.000000
1700418600.000000
1700418600.000000
1702372339

 

1701973800.000000- 1702372339 =

1701455400.000000- 1702372339= 

like this 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| mvexpand latest
| eval diff=now - latest

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| mvexpand latest
| eval diff=now - latest
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...