Getting Data In

How to divide yesterdays data with today's data?

yesh_9
Engager

Hello Folks ,

Need help. Every day new file generates with a FileSizeBytes value, I need to compare the yesterday's FileSizeBytes value with today's FileSizeBytes value. and store the result value on a new field.

Ex:      _time                                                                        FileSizeBytes 

           2021-11-13 02:21:51.327                             116786105

           2021-11-12 02:15:18.357                              116757352

Job runs from Tue- Sat

Labels (5)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| sort 0 _time
| streamstats values(FileSizeBytes) as previousFileSizeBytes current=f window=1

yesh_9
Engager

@ITWhisperer  Appreciate your help sir.

I have added the below line for getting the exact result.

| eval result = fileSizeBytes-PerviousFileSizeBytes . Which stores the result in result filed. 

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 3)

Welcome back to Splunk Classroom Chronicles, our ongoing blog series that pulls back the curtain on Splunk ...

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Almost Too Eventful Assurance: Part 1

Modern IT and Network teams still struggle with too many alerts and isolating issues before they are notified. ...