<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to find deltas for multiple fields generically in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-deltas-for-multiple-fields-generically/m-p/42441#M9920</link>
    <description>&lt;P&gt;Currently, the query  ... |  timechart span=1hr count by term limit=10 &lt;/P&gt;

&lt;P&gt;gives me &lt;/P&gt;

&lt;P&gt;_time    apple    orange   banana&lt;/P&gt;

&lt;P&gt;3:00pm 123        138    100&lt;/P&gt;

&lt;P&gt;4:00pm 132         102   129 &lt;/P&gt;

&lt;P&gt;Is there a way to find the deltas of each term without naming each individual field in the query? The reason is because the field names (terms) may change (there are several hundred possible terms).&lt;/P&gt;

&lt;P&gt;I only know how to do  ... | delta apple p=1 as apple_d  &lt;/P&gt;

&lt;P&gt;but unfortunately, the apple term might be something else. So I am hoping for soemthing like ... | delta all_fields_except_time* p=1 as field_name_d &lt;/P&gt;

&lt;P&gt;Ultimately I want a table like _time apple_d orange_ d banana_d&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:50:54 GMT</pubDate>
    <dc:creator>benobviate</dc:creator>
    <dc:date>2020-09-28T12:50:54Z</dc:date>
    <item>
      <title>How to find deltas for multiple fields generically</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-deltas-for-multiple-fields-generically/m-p/42441#M9920</link>
      <description>&lt;P&gt;Currently, the query  ... |  timechart span=1hr count by term limit=10 &lt;/P&gt;

&lt;P&gt;gives me &lt;/P&gt;

&lt;P&gt;_time    apple    orange   banana&lt;/P&gt;

&lt;P&gt;3:00pm 123        138    100&lt;/P&gt;

&lt;P&gt;4:00pm 132         102   129 &lt;/P&gt;

&lt;P&gt;Is there a way to find the deltas of each term without naming each individual field in the query? The reason is because the field names (terms) may change (there are several hundred possible terms).&lt;/P&gt;

&lt;P&gt;I only know how to do  ... | delta apple p=1 as apple_d  &lt;/P&gt;

&lt;P&gt;but unfortunately, the apple term might be something else. So I am hoping for soemthing like ... | delta all_fields_except_time* p=1 as field_name_d &lt;/P&gt;

&lt;P&gt;Ultimately I want a table like _time apple_d orange_ d banana_d&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:50:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-deltas-for-multiple-fields-generically/m-p/42441#M9920</guid>
      <dc:creator>benobviate</dc:creator>
      <dc:date>2020-09-28T12:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to find deltas for multiple fields generically</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-deltas-for-multiple-fields-generically/m-p/42442#M9921</link>
      <description>&lt;P&gt;This will give the absolute delta, with no indication of which value is bigger:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | streamstats range(*) window=2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The delta command does indeed not like wildcards.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2012 10:44:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-deltas-for-multiple-fields-generically/m-p/42442#M9921</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2012-11-22T10:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to find deltas for multiple fields generically</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-deltas-for-multiple-fields-generically/m-p/42443#M9922</link>
      <description>&lt;P&gt;finally a use for untable. !&lt;BR /&gt;&lt;BR /&gt;
(not really - it you don't do timechart 1st, you wont be in this predicament )&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | untable _time fruit count | streamstats current=false window=1 global=false first(count) as p_count by fruit | eval delta=p_count-count | xyseries _time fruit delta
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;realistically, you would do the streamstats, manually calculate the delta, then do timechart on the delta field&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2012 17:53:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-deltas-for-multiple-fields-generically/m-p/42443#M9922</guid>
      <dc:creator>jonuwz</dc:creator>
      <dc:date>2012-11-22T17:53:09Z</dc:date>
    </item>
  </channel>
</rss>

