I am querying a change in a value each week over last 4 weeks. Ineed to know the value from the week before the search window to work out the change correctly.
index=ind sourcetype=src (type=instrument) earliest=-5w@w+1d latest=@w+1d
| bucket _time span=7d
| stats max(reading) as WeekMax by _time
| streamstats current=f last(WeekMax) as LastWeekMax
| eval WeekDelta = WeekMax - LastWeekMax
| eval WeekDelta = if(WeekDelta < 0, 0.000000, WeekDelta)
| table _time, WeekMax, WeekDelta
I don't want to show the time for the week before the query (-5th week). Any tips on how to change this query to only show results for last 4 weeks but still calculating the change correctly?
Thanks
| where _time > relative_time(now(),"-4w@w+1d")