I need to display value (string) of a field depending on the value of this field in previous event.
Something like this :
if previous_event.field = "toto" then display current_event.field else display "anomaly"
I've found something interesting with "transatcion" by I can't achieve to do this.
Any help is welcome.
Thanks in advance.
autoregress is going to be the simplests solution for you.
| autoregress myfield as prev_myfield
| eval display_field=if(prev_myfield=="toto",myfield,"anomoly")
if you need something more advanced than auoregress, streamstats allows you to do "by" clasuses etc.
View solution in original post
That does the trick, excellent ! Many thanks.