Splunk Search

How to calculate changes over multiple column

Path Finder

I have the following output from my base search:

alt text

It shows accumulative value for each sampling time for each interface. Is there a good way to calculate the change for each sampling time for each interface and show the result in a similar table format?


0 Karma

Super Champion

you can use a streamstats command.

|streamstats window=1 current=f values(*) as prev*|foreach TenGig* [eval diff_<<FIELD>>='<<FIELD>>'-prev<<MATCHSTR>>]


Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!