You have the event immediately after, that's 51 minutes later. Remember that splunk generally* returns search events in reverse chronological order (from most recent to oldest), so - unless you resort them - you're calculating streamstats from the most recent events. Which means that it's the difference from the previous event _in the event list_, not chronologically. So - in your case - you're calculating the difference from the event that happened immediately _after_ the one you're analysing. *There are some additional factors affecting event order if you're using commands like append or multisearch.
... View more