I have the following summary index
_time Type Number
11/14/11 3:00:53.000 PM New 56802
11/14/11 2:00:44.000 PM New 56581
11/14/11 1:01:00.000 PM New 56459
11/14/11 12:00:51.000 PM New 56327
11/14/11 11:00:42.000 AM New 56187
11/14/11 10:00:58.000 AM New 55998
11/14/11 9:01:08.000 AM New 55724
11/14/11 8:01:12.000 AM New 55282
I have been not able to find a query that substract the last event "Number" with the previous one. For example
Events:
_time Type Number
11/14/11 3:00:53.000 PM New 56802
11/14/11 2:00:44.000 PM New 56581
New Number = 56802 - 56581
Result set:
New Number = 301
Thanks,
This is precisely what you could use the delta
command for.
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Delta
This is precisely what you could use the delta
command for.
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Delta
No problem. Could you please mark my answer as accepted? Thanks!
Thanks for your help