I'm trying to schedule a report that snaps to the last month.
For example, I use -1mon@mon this snaps to -30 days.
Today is the 10th and my reports show 1 month back from the 10th usine -1mon@mon
How to I get it to show just that last month?
Simple answer: Use just @mon.
This will tell Splunk to look at the last month, if you put something in front (i.e. -1mon@mon) it looks for the last month from that point going back (the first start of month since 1mon ago).