How can I compare the t_done event in Splunk Web performance for last week's data and current data?
that is the example using timewrap:
source="Perfmon:CPU Load" counter="% Processor Time" host="SERVER01" earliest=-1d@d latest=-0d@d
| timechart avg(Value) span=1h
| timewrap w
| where strftime(_time, "%A") == " day of the week"
For more informations, try following this link:
Try using the Timewrap app. You can use it to compare two time ranges by adding it your search.
t_done=* earliest=-2w@w latest=@w | timechart avg(t_done) | timewrap w