Splunk Dev

financial Calendar

DanielaEstera
Explorer

Hi, community members

 

I am trying to write a query that looks like this:

| dbxquery query="select VULNERABILITY_LIFECYCLE, SOURCE, CLOSURE_FY, CLOSURE_QUARTER, CLOSURE_DATE
from table [...]"
| eval MONTH=strftime(strptime(CLOSURE_DATE,"%Y-%m-%d %H:%M:%S"),"%m")
| eval SURSA = if(SOURCE!="QUALYS-P","Confirmed", "Potential")
| chart count over MONTH by SURSA

 

My problem is that I want this chart to represent a financial year, not a calendar year. How can I do this? (also,  without skipping months)

DanielaEstera_0-1632391869249.png

 

Thank you for your support,

Daniela

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Include the year in the MONTH field? Add 8/subtract 4 (assuming April) and take a modulus 12 and add 1?

0 Karma

DanielaEstera
Explorer

not quite sure. did you mean :

| eval MONTH=strftime(strptime(CLOSURE_DATE,"%Y-%m-%d %H:%M:%S"),"%m-%Y")
| eval luna = (MONTH + 4 )mod 12 + 1

??

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The values will be sorted so year should come before month.

| eval MONTH=strftime(strptime(CLOSURE_DATE,"%Y-%m-%d %H:%M:%S"),"%Y-%m")

or change the month so the April is 1 and March is 12

| eval luna = ((MONTH + 8 ) % 12) + 1
0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...