Splunk Search

earliest and latest value from a chart

New Member

Hello community,

I am searching since few days a solution to display the earliest and latest value from a chart into a dashboard.

here is my query;

<query>index=main Name=volume_* | chart sum("Used Capacity TB") AS "Used Capacity TB", sum("Total Capacity TB") AS "Total Capacity TB" by _time span=7d</query>

I would like to extract the earliest and latest value and then substract the latest-earliest divided by the number of days.



values of 

earliest is 50

latest is 52

the calculation will be 

52-50 = 2

2/7d = 0.286


Thank you!


Labels (1)
0 Karma


Use addinfo - for example

| makeresults 
| addinfo
| fieldformat info_min_time=strftime(info_min_time,"%Y-%m-%d %H:%M:%S") 
| fieldformat info_max_time=strftime(info_max_time,"%Y-%m-%d %H:%M:%S")
0 Karma
Get Updates on the Splunk Community!

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! &#x1f308; In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...