Hi Splunkers, I have some data set with Ticket start and end times, I have created
index=x sourcetype=y
| eval opentickets=if(start>relative_time(now(),"@y"),"Opened","")
| eval closetickets = if(end>relative_time(now(),"@y"),"Closed","")
| bin _time span=1mon
| eventstats count(eval(openticketstate="Opened")) as Opened count(eval(closeticketstat="Closed")) as Closed by _time
| eval diff = Opened-Closed
| timechart values(Closed) as Closed values(Opened) as Opened
Which gives me a nice table of:
_time,Closed,Opened
2017-01,108,1
2017-02,27,7
2017-03, 86,64
2017-04,38,33
Question is I have a static number from last year and I need another column TotalOpenTickets that updates this number along with the timechart. So every month, it needs to get previous months TotalOpenTickets count, add Opened count substitute Closed count. My goal is to get the result set of ( let's say static TotalOpenTickets is 200) similar to:
_time, Closed, Opened, TotalOpenTickets
2017-01 ,108 ,1 ,93
2017-02 ,27 ,7 ,73
2017-03 ,86 ,66 ,53
2017-04 ,38 ,58 ,73
I hope I explained well. Thanks for reading.
... View more