Hi Legends
How do I give bit more meaningful names for fields last_sum and first_sum in below query?
i.e. something like sum_February and sum_March?
Is there a way to use the value of date_month field in a search?
streamstats current=f window=1 last(sum) as last_sum first(sum) as first_sum
Hi @dvg06
Assuming you want something dynamic, then this run anywhere example shows a method to use...
| makeresults | eval last_sum="100", first_sum="200"
| eval current_month=strftime(now(), "%B"), previous_month=strftime(relative_time(now(), "-1month@month"), "%B")
,last_{current_month}=last_sum, first_{previous_month}=first_sum
| table last* first*
Hope that helps