Splunk Search

How can I get the previous value of the field that I'm computing in my eval

pradeepkumarg
Influencer

I'm computing a field using eval statement and in the same eval I want to check what is the value for the same field in previous event

Apparently I need autoregress on the same field which I'm computing currently. (fieldA in the below example)

|eval fieldA = if(prev_fieldA=fieldB,"Y","N")
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You can copy over neighbouring field values using streamstats:

... | streamstats current=f window=1 last(fieldA) as prev_fieldA | ...

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You can copy over neighbouring field values using streamstats:

... | streamstats current=f window=1 last(fieldA) as prev_fieldA | ...

martin_mueller
SplunkTrust
SplunkTrust

prev_fieldA is the neighbouring value of fieldA. Run this dummy query to see for yourself:

| stats count as fieldA | eval fieldA = "a b c d d e f" | makemv fieldA | mvexpand fieldA | streamstats current=f window=1 last(fieldA) as prev_fieldA | eval equal = if(fieldA==prev_fieldA, "yes", "no")

pradeepkumarg
Influencer

How can I club the above statement where I'm actually computing fieldA ?

prev_fieldA determines the current fieldA

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...