Splunk Search

How to add the sum of previous row data to next next row

mnarmada
Path Finder

Hello,

I have 3 questions here.
1)
Code WeeK RFS1 RFS2 RFS3 decision
1234 W1 5 5 5
1234 W2 5 5 6
1234 W3 1 2 2

etc.,
For the First week i.e, W1, Decision should be Zero.
Decision = 0
I have a formula i.e., Decision(W2)=RFS3(W1)+RFS3(W2)-Decision( W1)
and
Decision(W3)=RFS3(W1+W2+W3)-Decision( W2+W1)
or
Decision(W3)=RFS3(sum of W1,W2,W3)-Decision( sum of W1, w2)
This should continues for all the weeks,
Like For 15th week,
Decision(W15)=RFS3(W1+W2+................+W14+W15)-Decision( W1+W2+.........+W14)

I have tried using addcols and sum commands but did not find the solution.

2)
After doing this, I have to create a column chart to show all the values on the column if I place cursor over that bar.
Like:
for week1, all the details like code, week, previous total of rfs3, current rfs3, previous decision and current decision.
I have used like below:

| eval All_details=tostring("Week: ")+'WEEK'+tostring(", CODE: ")+'CODE''+tostring(", Current Week RFS3: ")+'RFS3'+tostring(", Next Week RFS3: ")+'prev_RFS3'+tostring(", Previous decision: ")+'prev_decision'+tostring(", (Current Week RFS3+Next Week RFS3-Previous decision)= Current decision: ")+'decision'

It is giving me all the details in a single line. But I want code in a line, week in a line and rfs3 in a line and soon.

3)
Also If I use chart by count command for the concatenated value, it is showing 15 records of data in the column chart and next records of data like other. How to show all the records in the chart.

Please help me to solve all my queries, a little urgent.

Thanks ℜgards,,
Narmada.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...