Splunk Search

Find "error1" count in server logs on or after last Thrusday as count1 , and before last Thrusday as count2

VS0909
Communicator

I need to find "errors1" in server logs that occurred on or after last "Thrusday" as "count1" , and "error1" that occurred before last "Thrusday" as "count2"

So, if today  is 16th, then all "error1" in server logs that occurred on 16th , 15th, 14th and 13th as "count1", and "error1" before 13th as "count2"

Sat

Sun

Mon

Tues

Wed

Thru

Fri

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

 

Please help!

Labels (7)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please see my response to your other similar question (one of the calculations will be slightly different since you are now looking at Thursday instead of Wednesday)

https://community.splunk.com/t5/Splunk-Search/Calculate-if-more-than-15-of-quot-error1-quot-in-serve... 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...