Splunk Dev

financial Calendar

DanielaEstera
Explorer

Hi, community members

 

I am trying to write a query that looks like this:

| dbxquery query="select VULNERABILITY_LIFECYCLE, SOURCE, CLOSURE_FY, CLOSURE_QUARTER, CLOSURE_DATE
from table [...]"
| eval MONTH=strftime(strptime(CLOSURE_DATE,"%Y-%m-%d %H:%M:%S"),"%m")
| eval SURSA = if(SOURCE!="QUALYS-P","Confirmed", "Potential")
| chart count over MONTH by SURSA

 

My problem is that I want this chart to represent a financial year, not a calendar year. How can I do this? (also,  without skipping months)

DanielaEstera_0-1632391869249.png

 

Thank you for your support,

Daniela

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Include the year in the MONTH field? Add 8/subtract 4 (assuming April) and take a modulus 12 and add 1?

0 Karma

DanielaEstera
Explorer

not quite sure. did you mean :

| eval MONTH=strftime(strptime(CLOSURE_DATE,"%Y-%m-%d %H:%M:%S"),"%m-%Y")
| eval luna = (MONTH + 4 )mod 12 + 1

??

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The values will be sorted so year should come before month.

| eval MONTH=strftime(strptime(CLOSURE_DATE,"%Y-%m-%d %H:%M:%S"),"%Y-%m")

or change the month so the April is 1 and March is 12

| eval luna = ((MONTH + 8 ) % 12) + 1
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...