Thank you so much for your help thus far! You've been amazing. I adjusted the dates as recommended but it still seems like the timeframes aren't being bucketed properly 😕 I used the following: | eval DATE0=if(_time >= relative_time(now(), "-1d@-d"),SCORE,0)
| eval DATE1=if(_time >= relative_time(now(), "-2d@-1d") AND _time < relative_time(now(),"-1d@d"),SCORE,0)
| eval DATE2=if(_time >= relative_time(now(), "-3d@-2d") AND _time < relative_time(now(),"-2d@d"),SCORE,0) | eval TREND_DAY1=if(DAY1 > (DAY0*1.05),1,0) | eval TREND_DAY2=if(DAY2 > (DAY0*1.10),1,0) | eval THRESHBREAK=if((TREND_DAY1 + TREND_DAY2) > 0,"TRUE","FALSE") | table _time CCAP NODE_COUNT HEALTH DAY0 DAY1 DAY2 TREND_DAY1 TREND_DAY2 BREAK _time TITLE ITEM_COUNT SCORE DAY0 DAY1 DAY2 TREND_DAY1 TREND_DAY2 BREAK 2021-11-22 TITLE2 3 52 0 52 0 1 0 TRUE 2021-11-22 TITLE3 2 63 0 63 0 1 0 TRUE 2021-11-23 TITLE3 2 30 30 0 0 0 0 FALSE 2021-11-24 TITLE2 2 46 46 0 0 0 0 FALSE As you can see, the ITEM_COUNT isn't being appropriately slotted into each DAY* column. It also seems somewhat random as to where it does appear. TITLE3 DAY0 should be 63 TITLE3 DAY1 should be 30 Yet it shows the opposite, and isn't showing for each row. 😕 I'm at a loss as to why it isn't outputting like expected... Is there something wrong with the way I've written the qeury? Or is there a better way that this can be done? thx!
... View more