Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to Sum Latest and Previous Field1 from multiple Field2.

$
0
0
Hi All, I have a problem to form the logic for sorting Latest and Previous Data to compare. Looking Field1=Status , and Field2=ID and sort by Latest compare with Previous. Search and Filter Data as below. Event 1 -> Time=10:02AM , Field1=100 , Field2=1 Event 2 -> Time=10:01AM, Field1=50, Field2=2 Event 3 -> Time=9:25AM, Field1=80, Field2=1 Event 4 -> Time=9:24AM, Field1=40, Field2=2 Event 5 -> Time=9:05AM, Field1=70, Field2=1 Event 6 -> Time=9:02AM, Field1=20, Field2=2 End Result Total Field1=150(which sum from 100+50) by picking latest from Field2=1&2. And compare previous result Field1=120(which sum from 80+40) by picking 2nd latest from Field2=1&2. My objective is to present the values different for Single Value Visualization. Thanks.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>