Hello folks, I am having a hard time getting the difference between two fields of the same record, where the search query returns multiple record set. The query uses streamstat to bring the "previous" field into the current record, here's a dummy that shows the same results | makeresults | eval RoleContents = "a;b;c" | eval _time = now() | append [| makeresults | eval RoleContents="b;c;d" | eval _time=now()-10] | append [| makeresults | eval RoleContents="a;d" | eval _time =now()-20] | streamstats current=f window=1 first(RoleContents) as LastRoleContents | sort _time | streamstats current=f window=1 first(RoleContents) as PrevRoleContents | sort - _time | makemv delim=";" RoleContents | makemv delim=";" PrevRoleContents | table RoleContents, PrevRoleContents What i am looking to acheive is within the row, to show the difference between those two fields, which will show , for each record returned, what changed in comparison to the previous record. Any help would be appreciated. Thanks
... View more