Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Time difference between events | multiple events that are in chronological order

$
0
0
I have the following data, and i want to find the time difference between start and end of the request for SID, need to ignore the START with no END, Note : in the below list Events (2,3), (4, 5), (10,11) are valid as they have start and end, the difference between these events is required _time SID REQUEST 1 2019-12-20 11:21:15.172 1h2fedk08swv29uCA9dPCRF START 2 2019-12-20 11:21:27.656 1h2fedk08swv29uCA9dPCRF START 3 2019-12-20 11:21:28.225 1h2fedk08swv29uCA9dPCRF END 4 2019-12-20 11:21:29.000 1h2fedk08swv29uCA9dPCRF START 5 2019-12-20 11:21:29.225 1h2fedk08swv29uCA9dPCRF END 6 2019-12-20 09:20:19.066 1h36phbXqfL9hXYLtXaFWtu START 7 2019-12-20 12:48:58.103 3qdu69MDOqaZTQ1WFld-C1N START 8 2019-12-20 11:13:51.873 Ieh_KV2UcC5oMqW6GFaVe26 START 9 2019-12-20 11:13:57.982 Ieh_KV2UcC5oMqW6GFaVe26 START 10 2019-12-20 11:14:08.252 Ieh_KV2UcC5oMqW6GFaVe26 START 11 2019-12-20 11:14:08.913 Ieh_KV2UcC5oMqW6GFaVe26 END

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>