I have the following output from my base search:
It shows accumulative value for each sampling time for each interface. Is there a good way to calculate the change for each sampling time for each interface and show the result in a similar table format?
Thanks
you can use a streamstats command.
|streamstats window=1 current=f values(*) as prev*|foreach TenGig* [eval diff_<<FIELD>>='<<FIELD>>'-prev<<MATCHSTR>>]
http://docs.splunk.com/Documentation/Splunk/6.6.0/SearchReference/Foreach