My search brings back data in a table like so:
_time|product|count
8/15/15 08:00:00|apples|500
8/15/15 08:00:00|oranges|800
8/15/15 08:00:00|plums|200
8/15/15 08:00:00|peaches|275
What I want is to have splunk compute the diff between the latest value above and the one just before it per product. So it ends up like:
8/15/15 08:00:00|apples|500|+50
8/15/15 08:00:00|oranges|800|+200
8/15/15 08:00:00|plums|200|-2
8/15/15 08:00:00|peaches|275|+80
Pretty sure I need to use streamstats and delta but can't get the combo right.
... View more