# Compare difference in field over time

**URL:** <https://discuss.elastic.co/t/compare-difference-in-field-over-time/139780>\
**Category:** Elasticsearch\
**Created:** [July 12, 2018, 2:31pm UTC](https://discuss.elastic.co/t/compare-difference-in-field-over-time/139780 "2018-07-12T14:31:58Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![shong](https://avatars.discourse-cdn.com/v4/letter/s/f19dbf/32.png) [@shong](https://discuss.elastic.co/u/shong)\
**Post date:** [July 12, 2018, 2:31pm UTC](https://discuss.elastic.co/t/compare-difference-in-field-over-time/139780/1 "2018-07-12T14:31:58Z")

</div>

HI, I have been trying to figure this out for few days, and I am still confused whether I can do this in logstash or in elasticsearch.

I want to analyze a specific field (i.e. src\_ip) and compare with src\_ip on different date to display the new IPs that has not been shown yet based on user pick time (--1d | -2d...).

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/0/80806dbd63529be23791b884ec29ea8584edb1a7.jpg)

If there is more IPs or OS are detected display the new ones.  
If there is less display removed ones.

How can I approach to get this value?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2018, 2:32pm UTC](https://discuss.elastic.co/t/compare-difference-in-field-over-time/139780/2 "2018-08-09T14:32:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
