I am capturing events every minute. Within the events, there is a continuously compounding field: "FlowTotal_Running_B".
At exactly 7am CT, I need to calculate the difference between the current value and the values 24hrs prior (this is "Daily_Total").
With this value I need to create a chart that lists the previous Daily_Totals by day.
Can someone help me out?
Thanks in Advance
Try something like this
your base search | bucket span=1m _time | where strftime(_time,"%H:%M")="07:00" | stats values(FlowTotal_Running_B) as FlowTotal_Running_B by _time | detla FlowTotal_Running_B as Daily_Total
Try something like this
your base search | bucket span=1m _time | where strftime(_time,"%H:%M")="07:00" | stats values(FlowTotal_Running_B) as FlowTotal_Running_B by _time | detla FlowTotal_Running_B as Daily_Total
Spot on. Thanks!
Glad it worked for you. Don't forget to mark it answered by clicking on "Accept"