<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: summarize stats by month in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740597#M240460</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207748"&gt;@mvasquez21&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1741015558161.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/37941i8532A6BE14DDE884/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1741015558161.png" alt="kiran_panchavat_0-1741015558161.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Mar 2025 15:26:03 GMT</pubDate>
    <dc:creator>kiran_panchavat</dc:creator>
    <dc:date>2025-03-03T15:26:03Z</dc:date>
    <item>
      <title>summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740594#M240459</link>
      <description>&lt;P&gt;I have this search to see logins to our splunk environment:&lt;/P&gt;&lt;P&gt;&amp;nbsp; index = _audit user="*" action="login attempt" info=succeeded | stats count by user&lt;/P&gt;&lt;P&gt;mgmt is asking to see the same data but instead of a "count" column, they want a column for each month. I assume it will be a table of some sort but can't figure out the date summarizing.&lt;/P&gt;&lt;P&gt;Here is an example of the individual entry:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Audit:&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;timestamp&lt;/SPAN&gt;=03-03-2025&lt;/SPAN&gt; &lt;SPAN class=""&gt;09:10:52.577&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;user=xxxxxx&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;action=login&lt;/SPAN&gt; &lt;SPAN class=""&gt;attempt&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;info=succeeded&lt;/SPAN&gt; &lt;SPAN class=""&gt;reason=user-initiated&lt;/SPAN&gt; &lt;SPAN class=""&gt;useragent=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Mozilla/5.0&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;Windows&lt;/SPAN&gt; &lt;SPAN class=""&gt;NT&lt;/SPAN&gt; &lt;SPAN class=""&gt;10.0&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class=""&gt;Win64&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class=""&gt;x64&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;AppleWebKit/537.36&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;KHTML&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;like&lt;/SPAN&gt; &lt;SPAN class=""&gt;Gecko&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class=""&gt;Chrome/133.0.0.0&lt;/SPAN&gt; &lt;SPAN class=""&gt;Safari/537.36&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;clientip=xxx.xxx.xxx.x&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;method=LDAP&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;session=17a169464fada764a1bac7310cac4c47]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;columns should be:&amp;nbsp; user&amp;nbsp; &amp;nbsp;monthA&amp;nbsp; &amp;nbsp; monthB&amp;nbsp; &amp;nbsp;monthc&lt;/P&gt;&lt;P&gt;with the counts under each month&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740594#M240459</guid>
      <dc:creator>mvasquez21</dc:creator>
      <dc:date>2025-03-03T15:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740597#M240460</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207748"&gt;@mvasquez21&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1741015558161.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/37941i8532A6BE14DDE884/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1741015558161.png" alt="kiran_panchavat_0-1741015558161.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:26:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740597#M240460</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-03T15:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740598#M240461</link>
      <description>&lt;P&gt;could i ask of you to paste that so my bad typing doesn't mess it up? Thanks so much!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:31:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740598#M240461</guid>
      <dc:creator>mvasquez21</dc:creator>
      <dc:date>2025-03-03T15:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740599#M240462</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207748"&gt;@mvasquez21&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;| makeresults count=20 &lt;BR /&gt;| eval _time=relative_time(now(), "-".(random()%180)."d") &lt;BR /&gt;| eval user="user".tostring(1+random()%5) &lt;BR /&gt;| eval action="login attempt", info="succeeded" &lt;BR /&gt;| eval month=strftime(_time, "%b %Y") &lt;BR /&gt;| chart count over user by month&lt;/PRE&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:34:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740599#M240462</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-03T15:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740600#M240463</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207748"&gt;@mvasquez21&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try this&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;index = _audit user="*" action="login attempt" info=succeeded&lt;BR /&gt;| eval _time=relative_time(now(), "-".(random()%180)."d") &lt;BR /&gt;| eval month=strftime(_time, "%b %Y") &lt;BR /&gt;| chart count over user by month&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:44:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740600#M240463</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-03T15:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740603#M240464</link>
      <description>&lt;P&gt;when using this one:&lt;/P&gt;&lt;PRE&gt;| makeresults count=20 &lt;BR /&gt;| eval _time=relative_time(now(), "-".(random()%180)."d") &lt;BR /&gt;| eval user="user".tostring(1+random()%5) &lt;BR /&gt;| eval action="login attempt", info="succeeded" &lt;BR /&gt;| eval month=strftime(_time, "%b %Y") &lt;BR /&gt;| chart count over user by month&lt;BR /&gt;&lt;BR /&gt;my results don't show the username:&lt;/PRE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mvasquez21_0-1741016486381.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/37942iAE0E458D9DE726B1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mvasquez21_0-1741016486381.png" alt="mvasquez21_0-1741016486381.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:41:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740603#M240464</guid>
      <dc:creator>mvasquez21</dc:creator>
      <dc:date>2025-03-03T15:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740604#M240465</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207748"&gt;@mvasquez21&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;makeresults is a &lt;STRONG&gt;command in Splunk&lt;/STRONG&gt; that generates synthetic (fake) data for testing, debugging, and query development &lt;STRONG&gt;without using an actual index&lt;/STRONG&gt;. You have to pass your original query.&amp;nbsp;&lt;/P&gt;&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740604#M240465</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-03T15:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740605#M240466</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207748"&gt;@mvasquez21&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have to use this query:&lt;/P&gt;&lt;PRE&gt;index = _audit user="*" action="login attempt" info=succeeded&lt;BR /&gt;| eval _time=relative_time(now(), "-".(random()%180)."d") &lt;BR /&gt;| eval month=strftime(_time, "%b %Y") &lt;BR /&gt;| chart count over user by month&lt;/PRE&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:44:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740605#M240466</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-03T15:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740606#M240467</link>
      <description>&lt;P&gt;when i try to append my search with it i get this error:&amp;nbsp;&lt;SPAN&gt;Error in 'makeresults' command: This command must be the first command of a search.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;index = _audit user="*" action="login attempt" info=succeeded | makeresults count=20&lt;BR /&gt;| eval _time=relative_time(now(), "-".(random()%180)."d")&lt;BR /&gt;| eval user="user".tostring(1+random()%5)&lt;BR /&gt;| eval action="login attempt", info="succeeded"&lt;BR /&gt;| eval month=strftime(_time, "%b %Y")&lt;BR /&gt;| chart count over user by month&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:44:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740606#M240467</guid>
      <dc:creator>mvasquez21</dc:creator>
      <dc:date>2025-03-03T15:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740608#M240468</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207748"&gt;@mvasquez21&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Don't append makeresults in your query:-&lt;/P&gt;&lt;P&gt;Use this&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;index = _audit user="*" action="login attempt" info=succeeded&lt;BR /&gt;| eval _time=relative_time(now(), "-".(random()%180)."d") &lt;BR /&gt;| eval month=strftime(_time, "%b %Y") &lt;BR /&gt;| chart count over user by month&lt;/PRE&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:45:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740608#M240468</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-03T15:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740609#M240469</link>
      <description>&lt;P&gt;perfect! you are a geniius&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:47:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740609#M240469</guid>
      <dc:creator>mvasquez21</dc:creator>
      <dc:date>2025-03-03T15:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740611#M240470</link>
      <description>&lt;P&gt;one last thing. this is listing the months alphabetically. any way to do it chronologically?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mvasquez21_0-1741017367701.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/37943iD34B7794B9F36162/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mvasquez21_0-1741017367701.png" alt="mvasquez21_0-1741017367701.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 15:56:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740611#M240470</guid>
      <dc:creator>mvasquez21</dc:creator>
      <dc:date>2025-03-03T15:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740614#M240472</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207748"&gt;@mvasquez21&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can definitely display the months chronologically instead of alphabetically. To achieve this, you need to convert the month representation (e.g., "Jan 2024") into a sortable format, like a timestamp or a year-month string (e.g., "2024-01").&lt;/P&gt;&lt;PRE&gt;index = _audit user="*" action="login attempt" info=succeeded&lt;BR /&gt;| eval _time=relative_time(now(), "-".(random()%180)."d") &lt;BR /&gt;| eval month=strftime(_time, "%Y-%m-%d"), sort_month=strftime(_time, "%Y-%m-%d") &lt;BR /&gt;| chart count over user by month &lt;BR /&gt;| sort + sort_month&lt;/PRE&gt;</description>
      <pubDate>Mon, 03 Mar 2025 16:09:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740614#M240472</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-03T16:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740616#M240473</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207748"&gt;@mvasquez21&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer my output:-&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1741018212912.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/37944iE4BFA91556BD35E7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1741018212912.png" alt="kiran_panchavat_0-1741018212912.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 16:10:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740616#M240473</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-03T16:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: summarize stats by month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740619#M240474</link>
      <description>&lt;P&gt;that last one seems to undo the month summarizing&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mvasquez21_0-1741019322688.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/37945iE66C97321D5590DE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mvasquez21_0-1741019322688.png" alt="mvasquez21_0-1741019322688.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 16:28:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/summarize-stats-by-month/m-p/740619#M240474</guid>
      <dc:creator>mvasquez21</dc:creator>
      <dc:date>2025-03-03T16:28:49Z</dc:date>
    </item>
  </channel>
</rss>

