I have a cumulative counter in a .csv log, the issue is, the software generating the .csv resets this counter from time to time.
The file looks like this, the counter is the second value.
What I look for is away to obtain the value of the counter disregarding resets, so in the example that would be 4480.01
I guess this can be done by summing the delta from last to previous value, however I have no Idea how to tell Splunk to ignore the delta when the last value is 0, and resume counting with the last high/non-zero value.
Thanks for the help, L
... View more