Hi all!
I am currently getting stats of current day as followed
Port Count
25 25
443 75
53 990
I wanted a table like this
Port Count(Previous Day) Count(Current Day)
25 25 30
443 75 40
53 990 50
My query is like this
Index=* | stats count by port
Please confirm is it possible
Please help!
Hi,
Have you tried to use the | appendcols function? or Just append ?
Your search here
| appendcols [ | search your search here earliest=-2d latest=-1d
| stats count as yesterday by Port ]
| stats count as today, sum(yesterday) as yesterday by Port
OR
Your search
| eval date="newer"
| append [ | search <your search> " earliest=-2d latest=-1d
| eval date="older"
| stats count by Port date ]
| stats count by Port date