Stats can be used to get the most recent X value of Y, for example:
| stats latest(x) by y
How do I get the most recent 2 values of X by Y for comparing change in the value of X.
Try this
your base search
| dedup 2 y
| stats latest(x) as Current earliest(x) as Previous by y
@the_wolverine, Try the following run anywhere search based on Splunk's _internal index (x is date_second and y is component)
index="_internal" sourcetype="splunkd" log_level!="INFO" component!="ConfContentsCache"
| stats list(date_second) as date_second by component
| eval latest=mvindex(date_second,0), previous=mvindex(date_second,1)
| fillnull value=0 latest previous
Try this
your base search
| dedup 2 y
| stats latest(x) as Current earliest(x) as Previous by y
You Rock!