If I search, I can see the count value of each field for one minute, and also want to know the sum count value 10 minutes before that.
At FFM_count 2 on 20170101 00:15:00
Please see the FFM_count sum from 201701 00:04 to 201701 00:14.
Is it possible for a splunk to express this way?
If possible, I'd like to know how.
host=* source=* earliest=-10m latest=now (Try this in your query and let me know whether it helps) . For more reference . Go through the below link.