Hello,
I want to show a number in a single value and other number in a trendline with the arrow.
For example A, I have this query:
index=quickpay host=f1cloud* "*CompraAutorizacionGenerar* response*" ("xxxxx") sourcetype=QP_busadapter| dedup logid | search "codResp"=0""| rex "\[(?\w+)ServiceStub]" | rex "#MID=(?\w+)#C*" | eval Comercio=case(Comercio=="xxxxx","FACL BF") | rex field=_raw "(?P.+)" | table _time Comercio responseDesc logid | addcoltotals labelfield=logid | timechart span=30m count(logid) as "Cantidad de autorizaciones"
And it shows like this:
Then, the results show like this:
But, if you see, image 1 shows the trendline with the difference between the last number and the penultimate number: 19 - 5 = 14 and it shows -14 in trendline.
But we want to show in trendline the penultimate number, 19, with the arrow downing, because the last number was 5.
How can I show this in Splunk?
Thank you!!
... View more