Splunk Search
Highlighted

How to return the most recent 2 values of X by Y?

Champion

Stats can be used to get the most recent X value of Y, for example:
| stats latest(x) by y

How do I get the most recent 2 values of X by Y for comparing change in the value of X.

0 Karma
Highlighted

Re: How to return the most recent 2 values of X by Y?

SplunkTrust
SplunkTrust

Try this

your base search
| dedup 2 y
| stats latest(x) as Current earliest(x) as Previous by y

View solution in original post

Highlighted

Re: How to return the most recent 2 values of X by Y?

Champion

You Rock!

0 Karma
Highlighted

Re: How to return the most recent 2 values of X by Y?

Legend

@thewolverine, Try the following run anywhere search based on Splunk's _internal index (x is datesecond and y is component)

index="_internal" sourcetype="splunkd" log_level!="INFO" component!="ConfContentsCache"
| stats list(date_second) as date_second by component
| eval latest=mvindex(date_second,0), previous=mvindex(date_second,1)
| fillnull value=0 latest previous



| eval message="Happy Splunking!!!"


0 Karma