Splunk Search

Compare stats of current day with previous day


Hi all!
I am currently getting stats of current day as followed
Port Count
25 25
443 75
53 990

I wanted a table like this

Port Count(Previous Day) Count(Current Day)
25 25 30
443 75 40
53 990 50

My query is like this

Index=* | stats count by port

Please confirm is it possible
Please help!

0 Karma

Path Finder

Have you tried to use the | appendcols function? or Just append ?

Your search here 
| appendcols [ | search your search here earliest=-2d latest=-1d 
| stats count as yesterday by Port ]
| stats count as today, sum(yesterday) as yesterday by Port


Your search
| eval date="newer"
| append  [ | search <your search> " earliest=-2d latest=-1d 
    |  eval date="older" 
    |  stats count by Port date ]
| stats count by Port date
0 Karma
