If I search, I can see the count value of each field for one minute, and also want to know the sum count value 10 minutes before that.
For example
At FFM_count 2 on 20170101 00:15:00
Please see the FFM_count sum from 201701 00:04 to 201701 00:14.
Is it possible for a splunk to express this way?
If possible, I'd like to know how.
Like this:
YOUR SEARCH HERE
| streamstats current=f window=10 sum(*count) AS sum_last_10_*count
Like this:
YOUR SEARCH HERE
| streamstats current=f window=10 sum(*count) AS sum_last_10_*count
Actually, I think that you need a | reverse
in there above the | streamstats
or you will be getting the 10 after, not before.
host=* source=* earliest=-10m latest=now (Try this in your query and let me know whether it helps) . For more reference . Go through the below link.
https://docs.splunk.com/Documentation/Splunk/7.0.3/SearchReference/SearchTimeModifiers
@mkoh - Do the above command helps you ..