accum
- 字段值为数字的事件,accum命令计算这些数字的累计值和总和。累计值既可以返回一至同一个字段,也可以返回到你新制定的字段。
accum <field> as new field
- Backlog 计算累加的总和(tickets_created-ticketes_resolved =Backlog,然后下一行的tickets_created+上一行的Backlog-tickets_resolved=Backlog)
- accum就是框内那列的求和等于右边的Backlog
- 大概的意思是accum的值等于它自己上一行的值加上field字段的值
index=main
| table month tickets_created ticket_resolved
| eval tickets_left=tickets_created-ticket_resolved
| accum tickets_left as backlog