Splunk Search

Find "error1" count in server logs on or after last Thrusday as count1 , and before last Thrusday as count2

VS0909
Communicator

I need to find "errors1" in server logs that occurred on or after last "Thrusday" as "count1" , and "error1" that occurred before last "Thrusday" as "count2"

So, if today  is 16th, then all "error1" in server logs that occurred on 16th , 15th, 14th and 13th as "count1", and "error1" before 13th as "count2"

Sat

Sun

Mon

Tues

Wed

Thru

Fri

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

 

Please help!

Labels (7)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please see my response to your other similar question (one of the calculations will be slightly different since you are now looking at Thursday instead of Wednesday)

https://community.splunk.com/t5/Splunk-Search/Calculate-if-more-than-15-of-quot-error1-quot-in-serve... 

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...