my search |eval _time= strftime(_time, "%Y-%m-%d")|stats latest(AssetRiskScore) as score by _time AssetNames | sort 0 - _time
| dedup 2 AssetNames | reverse
| streamstats current=f last(score) AS prev_score BY AssetNames
| eval change = score - prev_score
|eval _time= strftime(_time, "%Y-%m-%d")
|stats latest(AssetRiskScore) as score by _time AssetNames
| sort 0 - _time
| dedup 2 AssetNames
| reverse
| streamstats current=f last(score) AS prev_score BY AssetNames
| eval change = score - prev_score
2020-04-15
_time
and AssetNames
this display latest AssetRiskScore
values as score
_time
ascendingAssetNames
_time
descendingscore
value(like autoregress
)change
|eval _time= strftime(_time, "%Y-%m-%d")
|stats latest(AssetRiskScore) as score by _time AssetNames
| sort 0 - _time
| dedup 2 AssetNames
| reverse
| streamstats current=f last(score) AS prev_score BY AssetNames
| eval change = score - prev_score
2020-04-15
_time
and AssetNames
this display latest AssetRiskScore
values as score
_time
ascendingAssetNames
_time
descendingscore
value(like autoregress
)change
If I make it:
|eval _time= strftime(_time, "%Y-%m-%d")
|stats range(AssetRiskScore) as change min(AssetRiskScore) as prev_score max(AssetRiskScore) as score by _time AssetNames
This is enough.