I have 2 values time received =161300 and time sent = 161259, and I want to get the time stamp difference which is 1.
diff time received- time sent gives 41 sec which is incorrect.
please help with the correct query.
the data given above is in hhmmss format
Splunk treats those two fields as integers so the difference between them is indeed 41. If the fields are really strings then you first have to convert them into integers.
... | eval recv = strptime(time_received, "%H%M%S"), sent = strptime(time_sent, "%H%M%S")
| eval diff = recv - sent