I am running the following query:
index="ABCi" sourcetype=DEF
| timechart span=1h count
| fields - _time
| streamstats current=t diff(count) as count_diff
| stats avg(count_diff)
BUT, I am receiving the following error:
Error in 'streamstats' command: The argument 'diff(count)' is invalid.
Can you please help?
Thanks
diff() isn't a stats aggregation function - you could use range() instead, and perhaps a window size of 2
| streamstats current=t window=2 diff(count) as count_diff