So lets say I have 4 events,
name="karina" age="23"
name="Karina" age = "67"
name="George" age="45"
name="George" age ="12"
I want to be able to get the difference and group these events by the name field (or whatever field that they have in common) to be able to get something like,
name="Karina" calc_age="44"
name="George" calc_age = "33"
I tried using delta, but I always get negative numbers and I don't know how to incorporate the group by in there.
You will need eventstats
OR streamstats
. Try this
| eventstats max(age) as max min(age) as min by name | eval diff=max-min | dedup name | table name max min diff