I have tried using bin command but as
index=test| bin span=1w _time | chart count as total_count by _time, action
But this gives me event count over a span of 30days for every 7 days.
Please help me understand how to aggregate events in index by week and by month.
Try
index=test| eval week=strftime(_time,"%Y-%U")|eval month=strftime(_time,"%Y-%m")|chart count as total_count by week,month