First question - see this question and answer. http://splunk-base.splunk.com/answers/39974/variable-file-name-in-outputcsv
Not sure exactly what you mean by your second question.
I think summary indexing might be better suited for solving this problem instead. See http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Usesummaryindexing
Thank you,
I search a way to have the average of a colomn not day by day but first day to "current" day for each day (day1 => avg(day1), day2 => avg(day1, day2), day N => avg(day1, ... , dayN).
And then to compare the value of a day with a previous average.
My idea was to save the average and the current date, then to import a previous average througt his date.