Hi guys,
I am looking for a splunk query for following table
JobName | Jobtime |
Job1 | 2021-05-01 22:19:23 |
2021-05-01 22:19:22 | |
2021-05-01 19:54:38 | |
2021-05-01 19:52:37 | |
Expected output:
JobName | Job time | Timecalculation | Totaltime |
Job1 | 2021-05-01 22:19:23 | 1( sec) from first two entries time difference | =1+121=122 seconds |
2021-05-01 22:19:22 | |||
2021-05-01 19:54:38 | 2 minutes:1 second from entries 3 and 4 = 121 seconds | ||
2021-05-01 19:52:37 |
Splunk works from events - what do your events look like? Are all the 4 timestamps in the same event? are the JobNames unique? Does the JobName appear in all events with the timestamps? Are there only ever 4 timestamps per JobName? Can there by fewer or more timestamps per JobName?