Delta based on running total


I'm a bit new to elastic and am probably missing something simple.

I'm trying to figure out how to display a range of dates with their associated numerical values plus one calculated field that takes the difference between yesterdays totals and today's totals to create a delta that represents the change between the two days.

I've been reading up on the various functions and haven't come across anything to do this yet. Can someone please point me in the right direction?

Thanks in advance,

I think that you have to use a pipeline aggregation for this.

I don't have a concrete example at hand but thought that it could help.

1 Like

Thanks! So maybe the Serial Differencing Aggregation?

I'm trying to find decent examples of it in use to understand it better and determine if it would work.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.