Splunk Search

Find "error1" count in server logs on or after last Thrusday as count1 , and before last Thrusday as count2

VS0909
Communicator

I need to find "errors1" in server logs that occurred on or after last "Thrusday" as "count1" , and "error1" that occurred before last "Thrusday" as "count2"

So, if today  is 16th, then all "error1" in server logs that occurred on 16th , 15th, 14th and 13th as "count1", and "error1" before 13th as "count2"

Sat

Sun

Mon

Tues

Wed

Thru

Fri

1

2

3

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

 

Please help!

Labels (7)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please see my response to your other similar question (one of the calculations will be slightly different since you are now looking at Thursday instead of Wednesday)

https://community.splunk.com/t5/Splunk-Search/Calculate-if-more-than-15-of-quot-error1-quot-in-serve... 

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...