Hi Everyone,
If I am searching through the past 4 weeks in one query, how can I break this data into two columns, one for previous 2 weeks, and one for latest 2 weeks, then sort by Latest 2 weeks?
In general, im using stats to display the amount of objects affected by errors occurring in a 4 week period but would like to see them displayed in two 2 week periods, sorted by the amount in the latest 2 weeks.
| stats dc(objects) as OBJ by errorMessage
| span -OBJ
CURRENT OUTPUT
ERROR MESSAGE
OBJ
message 1
1792
message 2
1210
message 3
957
DESIRED OUTPUT
ERROR MESSAGE
LATEST 2 WEEKS
PREVIOUS 2 WEEKS
message 1
967
825
message 2
872
666
message 3
103
854
Thanks all,
Corey
... View more