I have a table:
Month Transactions
Mar 2000
April 3000
I want to display the difference of April - May and also the % reduction in Splunk. Is there a way to do that
Hi @sudeep5689,
you can use the delta command:
your_search
| timechart span=1mon count
| delta count AS countdiff
| eval perc=countdiff/count*100
Ciao.
Giuseppe
It didnt worked out