Dashboards & Visualizations

comparing the filed value with previous value

supraja
Path Finder

supraja_0-1664349228799.png

how to bring previous value by using value ?? could someone help me please.

Tags (1)
0 Karma

supraja
Path Finder

this solution is not working , we need to take considertation of time as well .. could you please provide any other solution

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| sort 0 _time
| streamstats window=1 current=f values(value) as previousValue
| reverse
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It looks like you want the value from the next event not the previous (although this does represent the previous in time looking at your data).

| reverse
| streamstats window=1 current=f values(value) as previousValue
| reverse
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...